From 26dda6aecb4ecb16b14055623ca38d8d62cd6919 Mon Sep 17 00:00:00 2001 From: Justin Wright Date: Tue, 24 Oct 2023 14:35:23 -0500 Subject: [PATCH 01/93] safer commit --- Scripts/Linux/LinuxScript.py | 1 + 1 file changed, 1 insertion(+) diff --git a/Scripts/Linux/LinuxScript.py b/Scripts/Linux/LinuxScript.py index 2ec3f2b..bd93a16 100644 --- a/Scripts/Linux/LinuxScript.py +++ b/Scripts/Linux/LinuxScript.py @@ -1,5 +1,6 @@ import subprocess import subprocess +import shlex class Tools: From bb3ebe53f17d7c6ef0b53d209b4edd8e468895b9 Mon Sep 17 00:00:00 2001 From: Aidan Herschede <124906765+aidantheunnammed@users.noreply.github.com> Date: Wed, 25 Oct 2023 12:17:07 -0500 Subject: [PATCH 02/93] Add files via upload --- TRACEBACK_PSSWDS.csv | 10 ++++++++++ 1 file changed, 10 insertions(+) create mode 100644 TRACEBACK_PSSWDS.csv diff --git a/TRACEBACK_PSSWDS.csv b/TRACEBACK_PSSWDS.csv new file mode 100644 index 0000000..ea6b2f8 --- /dev/null +++ b/TRACEBACK_PSSWDS.csv @@ -0,0 +1,10 @@ +ARG0n#5128?? +C0balt_404!?! +G0ld3ngLObe!? +tUNgstt3n!_! +OXygENLUhvz! +$ilveredMAR$1 + +IND1um__vs?? +M0Ngol14#124 +T1M3I$FLEETN From 270d3083c00aa469bf846c1b397c45ec12bd5dbd Mon Sep 17 00:00:00 2001 From: Aidan Herschede <124906765+aidantheunnammed@users.noreply.github.com> Date: Wed, 25 Oct 2023 12:22:31 -0500 Subject: [PATCH 03/93] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index d9ff035..17e5429 100644 --- a/README.md +++ b/README.md @@ -7,7 +7,7 @@ | Bash.script.for.CP.txt| NotMaxwell | Runs on windows, no known bugs. | | Linux CyberPatriot Checklist.pdf | Unknown | Should have all of the to-do items for Linux. | | Windows CyberPatriot Checklist.txt | Unknown | Should have all of the to-do items for Windows. | -| Waffl3.ps1 | Justintimefordinner | Bash script, unkown usage. | +| Waffl3.ps1 | Justintimefordinner | Bash script, unknown usage. | | LinuxScript.py | jman5213 | Python sctipt, mostly incomplete. Can be edited [here.](https://replit.com/join/fbzrymvbux-jman5213) | \**All checklists should be in the shared Google Drive on your school account.* From eb00b69e8b33e69f96554344cbf6529785452d9b Mon Sep 17 00:00:00 2001 From: Aidan Herschede <124906765+aidantheunnammed@users.noreply.github.com> Date: Wed, 25 Oct 2023 12:26:54 -0500 Subject: [PATCH 04/93] Update README.md --- README.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 17e5429..1f646ff 100644 --- a/README.md +++ b/README.md @@ -5,10 +5,11 @@ | File | Added by | Desc. | | :-----| :---------| :------| | Bash.script.for.CP.txt| NotMaxwell | Runs on windows, no known bugs. | -| Linux CyberPatriot Checklist.pdf | Unknown | Should have all of the to-do items for Linux. | -| Windows CyberPatriot Checklist.txt | Unknown | Should have all of the to-do items for Windows. | +| Linux CyberPatriot Checklist.pdf | zumlar/SavageCabbage39 | Should have all of the to-do items for Linux. | +| Windows CyberPatriot Checklist.txt | aidantheunnammed | Should have all of the to-do items for Windows. | | Waffl3.ps1 | Justintimefordinner | Bash script, unknown usage. | | LinuxScript.py | jman5213 | Python sctipt, mostly incomplete. Can be edited [here.](https://replit.com/join/fbzrymvbux-jman5213) | +| TRACEBACK_PSSWDS.csv | aidantheunnammed | All our passwords, 12 characters with all specifications. | \**All checklists should be in the shared Google Drive on your school account.* From 4771b87c3157228a9c30df9c46301f81a4684692 Mon Sep 17 00:00:00 2001 From: Aidan Herschede <124906765+aidantheunnammed@users.noreply.github.com> Date: Wed, 25 Oct 2023 12:32:43 -0500 Subject: [PATCH 05/93] Add files via upload --- Linux CyberPatriot Checklist.txt | 70 ++++++++++++++++++++++++++++++++ 1 file changed, 70 insertions(+) create mode 100644 Linux CyberPatriot Checklist.txt diff --git a/Linux CyberPatriot Checklist.txt b/Linux CyberPatriot Checklist.txt new file mode 100644 index 0000000..306a899 --- /dev/null +++ b/Linux CyberPatriot Checklist.txt @@ -0,0 +1,70 @@ +PRIORITY +* Open README +* Solve Forensics +* enable/disable ssh (depending on read me)(install openssh-service to enable/ “systemctl stop ssh” then “systemctl disable ssh” to disable) +* Check for daily updates in Software and Updates (Ubuntu specific) +* Remove/Change user accounts/admin privileges +* Fix permissions +* Delete hacking tools (like wireshark) +* Set password requirements. (check below for detail) +* Install and Enable gufw (Terminal> “sudo apt install gufw”> type “gufw” and make status=ON and Incoming=Reject) +* Update software (Terminal> “sudo apt-update” > “sudo apt-upgrade”) +* Change insecure password + + + + +Security tools to install (“sudo apt install [PROGRAM NAME]”) +* Clamav (open it with “clamscan” after install)(virus removal tool) +* Gufw(firewall) +* Openssh-server(ssh service) +* libpam-cracklib(creates better password policies) +* Bum (Boot Up Manager) (Use “sudo bum” to run) + + +Looking for media files +* Use “ls -la” to also view hidden files +* To search for files use “locate *[filetype]” + * .mp3 + * .mp4 + * .jpg (careful with these as some may be important) + * .avi + * .wav + * .midi + * .bmp + * .gif + * .jpeg +* “rm [PathToFile]” + + +For solving forensics +* Custom script wip + + + + +For password requirements + Pam.d +1. MAKE SURE libpam-cracklib IS INSTALLED!!!! +2. Through terminal (“cd etc/pam.d/”) +3. “Sudo nano common-password” +4. Find the line that says “pam_unix.so” and add “remember=5” +5. Find the line that says “pam_cracklib.so” and add “ucredit=-1 lcredit=-1 dcredit=-1 ocredit=-1” (Enforces password complexity) + + +1. Through terminal (“sudo gedit /etc/pam.d/common-auth”) +2. At the end of the file add “auth required pam_tally2.so deny=5 onerr=fail unlock_time=1800” (Sets the allowed failed login attempts to 5) + + + Login.defs +1. Go to terminal (“gedit /etc/login.defs”) +2. Set “PASS_MAX_DAYS” to “90” +3. Set “PASS_MIN_DAYS” to “10” +4. Set “PASS_WARN_AGE” to “7” + + + + +Disable guest accounts +1. Go to terminal (“sudo nano /etc/lightdm/lightdm.conf”)(might be “users.conf”) +2. Add the line “allow-guest=false” at the bottom of the file \ No newline at end of file From cdc4f06c649377b5b9b50e3de5b4ea6b316f04f4 Mon Sep 17 00:00:00 2001 From: Aidan Herschede <124906765+aidantheunnammed@users.noreply.github.com> Date: Wed, 25 Oct 2023 12:32:58 -0500 Subject: [PATCH 06/93] Delete Linux CyberPatriot Checklist.pdf --- Linux CyberPatriot Checklist.pdf | Bin 52858 -> 0 bytes 1 file changed, 0 insertions(+), 0 deletions(-) delete mode 100644 Linux CyberPatriot Checklist.pdf diff --git a/Linux CyberPatriot Checklist.pdf b/Linux CyberPatriot Checklist.pdf deleted file mode 100644 index 7dcdad331c60733bf4dacba31427a3adc9d91f59..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 52858 zcmce-W0Y;p(k@u$F59+k+qP|Emu=g&UA4=$ZQJ%P++aG0r`MX}iJ6&^ zkuxI48kzCrnk4eVqBIP&%upl?7iW7=4EXf;c7~Qv+}w1^7S7ft_~gM~U@6Ng!>tcUDDb{l5&A*TS zUiWm!AKsqDs{N(E`g^nEyN0*(@qBT8qIdtb@_qGwm*JdSaQgMf_p1B)>-iKa_?@pq zl-tXAg}uA2XZY_-M=swTufyz@(sORl_55cmP^zlZn9X;a-eGAHaB>32%IAsi^*6TB zwC|el*Gx^YqA*cnwi73QC@=+BxpeTu7Q(wddp|+SVnotkrBgRaC~TvMdh2#|4(zgg zND7iRK6~zigA=F43e2En ztr_L@J$}e^OG5X~yaAWWJ}^^kMrJlf?$X-l0b63ny4`uH`2A-&K)x?i|aUuT8PxC z-ALF~2X|(N)0Vnr^QTN@NG)OgA=gfuf(p4LnAfB~J^oZTg+3rNV68>9-f{1oNcbec zIb}ut;Vq(1u~~R&MM6Ef?4c%bwC$YY!}4feNWy?Dn!8WEwxDNOr*F|{d(81(j(0Cl znDUg0sqa$}30ys2COwXGWGwaOZs!{x)?h8YJRq)MELoxHKq=aypTKQ#yM_^w0X~^D z8SrtmoUx8lDT@%Q>O33@Nnw~p+zeQxf{Y)^xn(=AZ%N}(U^`lt4jae61VX~Np0_X;WJOj__!k9vz~oMuEPP$c_qd)0lkMxVM|(JsFN&k8WL? zSD)_?Qt4? zEmEj74fv#BDv>j7ISM$`I{=W?)DZ5g(%oh5pl3R?_GFKiH(L~`6$zOAH72L9^dge9TgGGG6woO&HdLf=#;hDEwvMTN|OYmtW*dUXvtNP zJf)eOKBg&ni40UHlNTq8(oFo&DSv@BO;(OZ)UhI)$ij(C<;2iVs)}%oztRF#B}5o( z41;E_i3`7q`XtrgX=v@9^U9EI&I65CS^HCnDf zAu3wtKRHgUOmS?v>{p!Mc0Y*Gx1xB**{}L-_xS;Gs@G=A6^yr(w`jaB*IF=ZEvez{?J6D^ZcDD>Xwi2(~bpNub z(>~}liB$@>%9+_MrqP00qrQKSF#SWxS)IFh7+@@xYkQA@fQaz*j#)-8N5rCqm z&84IETgSboM&HhcOPWa$(uq-Az<-5y4evB;goPR^xd9B4J~*xqc465Gny)w!(A88|ANt~iwL0>|7ifd`sylGKt)q$deCVH- zH4vETn$`(OBS|o#8cAf#4Dzdu^P^aB4WWF%;25QjqwM0C>Ny|dY{DTyq4tUR1dLWg zJ=CU4Kb(a508GsO;mCNUtiqdmPGAn@(-$AjBc8nLD@uFa&?=BW#-E~+42}m6SV+rC zfy;hGhfEf${e`0r{?S5{Rq*rgCdoHp-{^r5v|c55{mRy2e~wO1!KrIE1_@W@TEbY5 zqU3#%_wir#sh3uD%i}&{S-*_KZVaw7OUV-Svj%$?YOHAmo1x33Jkt>5k(L467iZqd zjp8-8ViLpDz`cpjfLv0oC&JkDt`b}$7CIZ$#4Mv&lJ`o+B1 z*h%RRM|-lpO-0*e)o!c1zf+6XQaGNGKc+?%L3)1Mg3t_GW#6koVAPUpucCj;A}$(Z zd*+#|UD#)_B&}ai>S7MSMQpP$H`KdhzSdqgpIVlS??a+j&F;)H=8A?`Q*#rRE1J=Ne+AXlCl-b-u;doG@=<%0uFu#^>&0r`R zs)G@lYAV~TM}ljv%g1|86j4YOl`}A-GJ)CUFxPcED}ysVV>gW9kLPUOdkvH~qr@tmYK(q*hQ}X~Fo{aDTC`KAqPyF!wi#-?E)H~^n?inM*&D!%BeU9sMUh3HKgv( z3lA^#WL9!UQIu6ntO?U5*ziTx^YIw|Fv3&ihBZ=g7FU8&QQE3A;za3_LK1rPu?pztoJ_MDkwkkhR#Fce&Hf9(C` z42MSJ@QonqnaJBuw8TLrtc|YlXBKLht@A4_HBGq@yypS(4(=Sp6RpOL zaE*zb-uMFB1C4474!4}K%sSBV$zt7Gc^%B5XZA3MY}tGW){ly56DJeO^>pgIBe?~i z822;W4)iaGf$R5PlIoFqt6R$%S+CqHfF(x|o)wzGOnx)?wA3aLkNQ;u>vdv~*Xx?^ zjs;iu3V5#1#-~y8IH&eDak)-8YWW!J+KW!4*z#^D-p-allI#n6r&aySmWkvi!hvh* ztXAL7cl`#>`=M@dk*RgD>%dpYC9LC%A)fDFhmXgSb+n_~_o-hIsDI@+KlnCw5a;() zUi4hw+%P;LNrV5!dY@cJwcZST&(mREX(0=JN6in|y?n1FT)tlzfP}Jr;)d3~WabP% zn!Ma>t?&_yJAY&>I##%Q5={xsKZ;?B$BayC+ZDNsV;1+W;|bh~ri&#}u$ar*1-T2R z4d*xAi>8V>b0o=U^sQ`@Kcq1#d(<1aFG$Og515{_F0+ku=S#~uitzAS@5f4}e*<%! z?4$jYHU3v3_FwrU$N#$|j)9$({eMg1v^Q+A*?xKN)TZHu5h|iZ@GIn55xd)7@R?@< zh&;?be)~IKy4Wy#sxC&EWxKG#A{qtFC8rJuS(-;YKZIQ3DdhP4?fmPBR0cY|4IAd#Tr%V=6EUWjm>b?2-(SsXw(z7hq>1ph}`F+1S^5y#S z?43>?%K06C_Iwb7dpzV0rO^~moNareyDbkzo#1G>aCNf)$DsJ;(EjPP0)$dPKDEuw zJgYO%v9VxuxQs_MX7GzfJAK^O=#U4!b906=blGs~NCLQ!4byy-FF&Nq${)Fsrvg*0hkZP)IugeaaGE`N0upZO_ z4z)=xk6@((3^E++4rvd5=P(HvvhndGL=G?qD-DamEx%}vsTbUPwwI_8v8d5p^Y1TK zzHM&ndxVVzOY$~H8m!E`_AbbP`P6Ih6?{d@$xC{2^B1_5ayFe}{%A?nP#%nB^Vbk3 z$3epiT1(vWT3LRMy6BJsp8`%?vHD+!0C{OR&Tp;b zibe3r&=yFbBA^CsONP_Ej#)m11efyWa0^g&m^*}JVY1ZnMxzwr7XS#Ceon0%7Qf!vhj7gdM;7xMJ!GBZL*toKaL8>u z0dnCR{6kP=p6AeWSS^m7BaL0vvmI8>nQ6ld(@kltjsda*e#5o}kGE9|NUs_R^z{k0 z?xG;q#f+$9!`USj#Gff}E6A1V&?U<&Ax&X*=rVUyUUao@|A6rdG!dn_V}2pO)(0#% z9;%sn=*;zIB9E*JVpoyV40eX2%j(TlR)_p3@%bt^^>N%2I_i|c7l@Xu@l+nL7&5>c zG3AM2PHe;pbN;@U9F{6MSh!|_(ZH^y?pg>=U>F6MB}od(WfXX~K;(PHvs?WDJu$qb zy%*Td%_PD;dOM;>j6)W-@HNgbziiRsV*BKr!7FWo%+)WmF8N*5CEKRt zsrD`h@UV$C6~ZxZIzvIh18ed!Ym9$5BP~DfDDc5TP`@ zZ%_H1)P&*w7ABvd@n}jiblPt4aJh{Rt$j!Y$uz{~n{tEZhqxxU#^cngbTq*d;br*P zuoADVYMiFI}zQL$m4O7s-qc1vL#48YRhB?2Qloc?rmAo$$uLWX<40|PUiz2S8pBZ4b?G6ez%DXBwF)M3Grr;NWj1~1!96H zL5cA5fHO~e{pL}P639@NlR;gaHb9C^*%`}lMN?7~59YSDz-FNdQx{DfShW-yyGV2L zE763O`1QwD8YQN~r;M(!ibz^C+KPuc?4TH2zMJ60j~(h)-nEMgtabIdlM?xVP5}UU6mluK@JEMQ!&d5hm|T+^t?}F#%>M_LW=GyEfPUwrF6hy_wIx)D6NXWm(0+FzWVqh+^X0n{l*4Y8c)?K9ylfT{fsjU`a;YLxLl+o{>F zcy>8_#Yr1Y7c<@Y>dXtGUNto2;BNq&csXmmL+&ggxd}jO;7T|#w}5B3*iI~Le}Ez4 zwEoqZsdMY7s6pJiZ1E#tC%{#bd|Q&aa&U+H2hP{yK$C+`3z?VhfRN1)_x zK%i`h1TeJxg}FLYTxvI_dJ_pbU|g7`thEzL$zc`Et1U+^Lqc zUm4hiXhr!_i#X8%LW=6s=g*6V-ll5f2Gy#i$Q2df$okcy_5Bh@&1GY<&M<(;I8A^} zOYAWiUGl+n3N=;qvjjXWWYbH3C78ZSJ~%+TBSRuN!}W_I#toc$m$ixZ%hg1Gx zi;a{_obk2(MHJI1o47gS(@EI;C<^|U6#6eIp#w!H;^r)-A3I89`SP_a& zj1~VMW?1ouD5ev&vvvNbRg@W@`QNRgEch({ZvCfS#>CjdK+w(&UyJ^yl9hoGpN)g@ z$F$H-KNDMLC;Wfd;2)bxKYX!~v%G=hzbbzy;fz}djs&g`G@%zkG7{~XDmsrX-^{5R#!fX~Rx#LE0Lss9hOJOeWm2jl;?rR#L} zQWjZe^QpM*^1ivE$(~-9-6J9Y927>nA;rf>&cj!^Zg? zdfFO|l`YI5fPU~EHO;=y7%|OmDvInf890s4DcQbbr$UxiHpAU>;?38?xBbHOqPU|u zQ(mD|Dx2LdfiEiT0FVqNS6)%G=ey@ivX7Skn5A@nJh}7nrgNacf$&xKa@wxKO zB1|3RwU_k9W+$i~xxiXsBI5~*un))S1Uq6;BsV)#NyBa{RL z*&o-$>TeKnzD)t%2>@hinty#o!!R(7K5}fT0%^Fz(Jc8cdgm`DJUHt7@LtExsERT$ zH%wj8#&TG8Ji5S3G}y^dxF|*+{p9_*8CniR2GoA@k$LutBFhZO_uxhT33HZgIhv*z zTofX)NUya5C>l!(Tuo|$NGEVDVcu7?n+Ck9gIFFUux+dF$QK6>p-$?r9(O$?y4t-L zn9kf=xuhK`vLg|&#-!!GEk%C(9$J-T!Q@2U?^|%+>6P=p7nx*Trd+*^- z>B(2Xu7(9>&P3#Lf1?6Sau+(?@g#gUurc3MQ=xhFSf|XD{406vU8;45OKMV~h$2RF z@aFw4c*I$_l~vrqKgtyn2QrQxp`D zudsC$A(`1LYA=91!_${o}H+Sr!p-eL%me} z>)_ch5+QORA#&kLmL`ANkfIC)CM1u}Ak~5+&|ZL6aGxYc`mdU6wK5t(y@OjY`UI7P z9XQXlm`%iEzj}hi!GasEs4%RT-f_ z78U&lE|q~SGXCWoEs6v+GvQ@5=7{E616=-cyx6DT`Y79v`j zWLk`J0K+`K(s`Wd5M7EWzntrboG#+KTPRoIA)dw_snfSf7HEr@82RDLWOY?gAnHr_ zUCNI8Rk$iLD|&0T403U^wykIIgsxn{6JU!3CHhiaQ<#&-K;$ZN7Gt_D`tt-S`YO)j z=+sF>;T0PyQmNsVrmAaeB&SBrNAZvh7g9k}L&(`_kQ2!=XPwt%Mp=1^CTxK!hpf%b z^1P*IVyxP^o0=$Q+PGW2#?qe%Oe6wNiCE!2Rf7{~IkG-xxDJnoYT3eJinDJIA^m8(<0V)(gv1YWr+{PJQDmS9IG7txfa+$J zDk2pR**skxdkoyf+#FaH&=~@6hseSc$N~v1B6FcXC2?PZ&-~_KfrKO|`aI^#kTckN zu97H7eW$0)CU#+U0&aCeTLY(jV~!bTa}{9FX8t*t=mK0Wzxn7vk_=bmRzYZ$pJbL} zP0jc;9hVX8%UZrTAq17Ah+4-lGrGV`6an)b74@A^BE=R0?;^sBrp)*rW38W*FX2A$ zkQjOt8a>@6)aSNjt=pl07lZR`;KD-B&*i!Z0?fjd;YxiL(L@Ua#@&ar^#SSzYa-3^k`8`Rer z?&;t$V#LCi>7lB?nkd~LCuGskQ4fLd7;Hxh?H zn{#x#6qhlt0Nbq6B&r6gh76H8@zt(-{2#&_C04H+y?G*ZCEN=IvtA~?)S3dVbUAl~ z^4x_kWK-GgGU=5ZQ8}hPJ{|tdT^?RxIwrcx1z3w*F&{(@pj0B*KTvx^zWtJ`)IPcA zQPRT3Wa-&gW;5m@>n@+EBG)n8Azad|orM%> zFNB(sYO_p_h~5IeCt8GB=3ur2nWvyB(?HZ%h`y13UroC;+<|fBNLUP;uq@bu>j?jz zQg8ySeZ+g53BBHyUn;jGZS{UlXM1t@sk{M`tDVUp{R7<=gC2Hk_f7ABUwHV!k+WEsvW!=vUc;;q)9xlv9x zH$Zj`w}bA({GoX`HflAC!}e-6u%RQ9DnNBzSn8nn2HYidGp85)<@asel9nB;yWD7V zN%~Cg3HUo%jzKEnMw~ZYEq{f@3+K?8qbGhRXj^Z{Gp=W1=fL+sk1~T%F+HzJq_9t;7a4lNvqAKt$OIW-lxr{_^#t?^NTN( zqLUIE>bKx;81s3OxIwyIs%wAhoPtz>xgDdyF6UpBas7U=Sm zv*KB|T8F#}ir!GPwrBy`;AjE2@m;cc2kDaCsp%>I9xyksphhEt`}Kh8y&6dLD#We3 z)&DLZH?6$cW|zlZHQ;p_;VU1EINaVU!ZV!G>us5p*Q8+y@rbpmq};EYN5fhZ7Aw-V z*!MN)xpeZ1{0=NDpZo6T=>N<(lNV|b?Rxk5LBSf0dvfH3(1Vnk1-BOXNbvYc*dCre zvAi%)6)R(y+Mw7HynPrx?&V5yt^Q)4oNi6}H;W#qU0O%h?2`%)L$x~UOE@>kH@|%` zx1ZN#Zc2Sl?9}_2>OI6Fenx)_S-p^?j&X&5rfLwckWrBu%s^m7qV8>H{S=IBKpuM)F5>(aP@cPDe`3+Ts{eS99kPw{lZlp ziOA}bODhg-sg%K!ZCDWDZ_%Hl5^N2j9?&Z`>tBCEnhnI9{R^^u0$)5lLazpSxsUW_ z9(p|bC(1*4O~$ArQ4IJVEzm4GnnIgKn)R$|SBC}G)#h<#PkRJ2uhRM$J)(JwYt#Ij z@8-}q3#c4ovjm=;aqZ+`XPr|5v^KHQBq(eH=hCadQzr8P%65kABDfCViM?W=+_FZYRBzXDe1pe+E2YCgtX0 zjIULN-Hi&*>x3y)qm(hQVu(PWEX+k*#ioRu89?9GkH9pnolw{u&Lq-Gmf3qa{nL7p zBaz~fuS)_-b$##z8~Uos`go915tey=3vT0_XCzE?j@? zoW|F$hBvKx%i_E?J$n^m5od5Z4BtJc8*=Z$aTTy4-+d1ER$#XfcO^Ywur9+WGZ6KR zcC`|wSXNXit57x6ioJ7CS-#VZ*S~^rwPVnZjUF*zi{|_+&|SjNy8`be)8M{2jkjmz z6HDjDUiis%MN5{@n#CDA-NyFly)E;uTl# zk>>Bp=v9=b8Ea) zTj;Gzdls-)wq_PNYXVZ|&H+`*GD{YX!LRzcFC!yF!!F!IL&L&PkrO1O;@PocvM@s? z77?#9toAQM3!{+6U?-6~-8EWXRsvk1@D~rz?BDjh^$JjdhEd22zr;Kw_g`Mu;$u{Q+J<8h=&PIhFT9tgznrra{#+>`&Oi4_%l|gp9#1J!5(4FA`1f&5Q%jZy(|qK zxk*R|$zb;`q9YYo$E@U#2JB6W{+hqOf2(H|3xJHEsGhCi0z*rB`$^I@3p?`rC5M0E9q#8@F6j?s?hgilrr(2r`xCCS5MJ| z_ym;kd%P6d0S1G7ZbAxUFWV4@r1J?4W}?i%lcaSoGv-&`jr1g(NA?+Bc6y?}Hh$tD z_}|mS<57zz>S zmxV>k@4{ z2U>#61nb{H^(aWBC77_)9uS%lIx{`w5 z<0H9>x*8GM^{@3igZ}UJ2ZhKI%&ce11$W5oPP!}-pWJV+O2R|8r2*#a$ZOwC;f*Cz zX#v_4SsWRR@_asqNrb_}rIScoCbV{C#d{aTth>VhL=9tMNZWik>5a)$PRw@v*I_Bl zqFfeYv3Oy)1xx`~{U{WLGR*)fXn0&>Qh96%N7~xVxPj3C?yJVwMiW~ zSb#FmsCS__x$YsWlUgG(2=O9w7XW7RO?sUyIBvPaPn4K$fiwZNg{X+cc2{bFYKoV7 zU7TePiC)i7fY@f;d!rHQiXQwkPXk6nZ{M~2&=xdzNf3PnFZ}q5pW+8vcdP+yQ(A** zqrCX5n;_jVbU-?@Xu)&|?j+km+)zG=@73BfXhCg3zk*xlOm|(^fi?xId$XM}ZZX4G z=23btPRGURuEo^=f6p!TViA8uwTNz)Vp(9_lCA@OaNN$cYF&bC3$ElHsg?k*LA#M%o7^nuJT{Jcw!T1b%CG@#oRaQtIWyhjwu5^4P~7RZqmaDJ+4TNBbKM2* z<=Z>{ZFU&j%CZ^!DD()uJJ5vn3UM3zNZt&HSJ>h2d79b_zXffbx+?G@vOQFN5OvqQ*u3uhgub7|lKF}XX zpRljEU5FgwzA3M~T|aASU~kW?Rd3JyMZDS>aCqn$%x>r-=`E25w43n$$fN7w%OfNX zkdNezux_8sgU+tmqnJM4C**7HBknEvC&nvB7u*NXE7#_>r~h|ekFbx_$SLq{Dq`${ z!LHgP!L8Lh#H$=9qI-IGeysn_JXtT&BSl^A7uYXgz5eJ2rrjQ!_t>>ZqxllNMApw$ zIO})5BAM@zAGuR3^WD*O=9|j;32m{^6ZgMFB;M-dOtB0frOms7#X_uPrjPRaW8sg1 zWY*8JrZcf(nVY|VWWIMA&hS3)HXeJ#Gr!O*7Ce8dlUcje)*oMrWqiMPSU-ISN^ZV; zR!e&B?J~c7m$x@2X}daSG!iYzP^3sNp?L#YXbGB`lIyAh~3#ENsEg|k@b(u@F0ptGVald za%e9_(PRNG2y6?R-zC_-x$Z_hpKL^3%fdD7ecq?+FAp-X1|*#p!1PHih=R}Q=~m&s zuZWm5b%~e6nErk9f`vqFWpD~@VQC9h+TOksHC7^Ae>aSM=Rv9DBle^r_UdVLIR&cs zO8y5Z5ewlhl;mkN)phMD)W~50h}u{qmi;r!b!LG1nSH|a$0N;pCS3j7((A& zilK!5on;Ho!PgcSH^c~7ay1Ih7}uWp2vv!%G~fsvDyvi`jaiHK2v-%(WYDx@ps=A> z21fBWps~{cSo(@6m5O9$b`YNhf&b-wJZY<c84Z=+(U6rlHu!4@0EEZT7=sF38>%q4OX?`nGXS*$zM2YOGe-KqGCC)L%5t?Eonz5*5wB7^%I4^DBwSWV0) zpfB6b&~J^gV%3ynyRBMeQfSa;veuYfJBx_ z5RCfsk0^jecF8LP7RfI90UYvkeg!g$9{`WwlrZq`2MPv-l2TO9tKiAOMH}AOp&S5dT~7BgFkv`bXf(yYcS<28${F zOMoNeO6)B>#ZG+yq-Q6*!e1z?eWBHprNOgd;pL zxWGR^^6#2H|8l#y{$2UZDF`iiO#~1dICD?_4d8WLi4CG9E24lr7=J>L2zYYAgnx@X z2#J46{|Hw3CjSB$WSfM4AkQ3FB(umoF{0z=X+CC>?|nO&KNwZ*cB_u6t(&6$%$hN7 zONSbJQ8Z7ymOA%D`3j~^ydqL2-;s`|Fuabr0l&d4@6kncDi$F3s_fsg~oj)&)#J*zBAiiiDc+sL-?qPgF=3=dQdyYYhL4-kGLDV2U z)Dt3qJ**A^CO#oJATS^R=Rip!@D@CcU@9{^RzI`pT1SyT52Jv#lyEqL!`e9=kMTVk zh|J1+=8Zim#N0$KA*(hA!d{$T;R@g9%pb)=zbS;_Twfy*SX>XIM4Uy%rm4Op(X_;U zRN`pS!%mF033FEV^ny&CxIPLIj$96nBbQs-8mSj!OrLI>J_%{c84GzpxjqsRqAzb# z!Fgtz)Y z`%B{+(?eaSH=0T+`j&EhgNB$_V18qSzq46In|}Z;)uCRMT#T4u8HYM$spu-LtspzAv7 z-F3Leir*s4?!vGsuRBsicuu8!-;QS;L&wF&l8xcG<9s~?Oj5S9j0NiqZi#k&vbIV+mgHVvk2oqG8X*JQJ0ArbaofhlRJe7d3sj-7xt7W34!)tChjv{>c21?P z{LWX_lJ*kAG^QGkw&K#PhJvmhM^)_=+20DfZv@k$0FAEG%7S~b3Mvto;L}RQM-__q ziaJVTy`{?F?UkiJSj^Q1@9A@`iCmYndnJoeAr|2|DdmFs9b{(2cCuTgh@NrS?l1&q z_L`%?_!ak54^$#3&*^23kv(~sWs=+697Ha7p7wd;f%~hw%$UeD;iAp?32n{!QE!nK z!4*MOBz)bb7ehpqiRB(HC|?9U0$`m&TJ!IC-mD+1jSdIHPe824)npYgN7J=1GHH?V zr=0DU6_)&Kt9^_j@g`R#8e1r50w%a%eXL>E!j!Q`0s$#Fe`vG+tgSoK)<9u#D$PeO zWA{RKg95&=cb6CP>*l_dOvh{Ne>LPc<`H8av{UZKBt;QE&T2p@BAAI7QL*BM>u7Y` z|4wc(X+HXsye{AV;)DEtgC=Gn*7pfzGpfZ$4nfSu%)g4Ba(Z(e)8xG7kSTt6#Bx|| zrl`w@%!-BlF40$mx7)7UutVR9KX?BGEM12s5kR-wU8?oCnj>sTW z;$ypz)E6VAglAe~wdD656jcl}OI4hX+CY?7hzzuo3Eu>1Vz4?R$%%VR>Pza(Gd5N3 zlAbJzxTh?@FpBBm&lhkIk1!X4oQI4$y1UqKo#-o}6Z)iYWS!U9Y+mm9?(T3`L^VgJ z(d%m;eX7>Mrk-K0#GcXS`2uHhPfAi@(mFG~x^hi=?6}4IgOvJRCM7YFZ=*GbV$$rl zGeaTML1C!Dm>HfGb*{^6T`ArB^s_RXn)hPZo=Vcp{iE+<8e2`=lJb%=18AW#2t8{e z%JeJJL%r1NNEPpgzOUn}?3(a&k1R`HTdK zQEG&0ZI9?rk1OCoaOl!*&AIrol$zK#8o+$c@cNmtS@Kqq7_5e=g+{#%GCx|!Ft&=K zbtAwiPQy8)qdYjeOq*p5>$vW2mUyvd@B=nyC>s@3lghB<-x0~la@Jv(L<-jhWtYTy zfU~>(KW;KAFy<|8GL0CnR3zRNI?j9I5_BzQ4kGpC{XI>atl3tS+EfGSNlAh_UXa{) zq~ArQDD87YOf(C24T6nJhsV4*5|o;0fZ~%U>{e@ez1|~OE4WtLnVWoCWza>6*9cGx zXcsh8W2&sdnC9Z?0Im-FaUQjjPTmO1i+zm8^$;kXV37 z%QBM0n+9di-tqLrE(Kd9vdD74S{vwF-WV8Ax+w^ypiR%PEZy3VlgX-rdDc7)ZwQQ3xkzhi^LR2HMG?743{8O@B zvUNH8QLk~^wcn}1fIE=dC}w8p&M5uZ6jSJEO%_DQ9~H)z(<i*{bP|BNsB{kv0>UH=cr#;tF#kx|<>sc^( zrSsS?1b3yg=K@Xh%@P03VS1jYvy3dHow@*89eE3y}Ncm&KpJdFN!GL*YDI329Mxn z@tACpp`i?TZ+fX=RS_>m28$Hc(q_vp%uAibym`>`)~&g*Djha`M=E;C5b9xys38{Xq?Q}3yB_yVFmHER@%W!Na?n|ipVqH3 z`call7i2mtR#_J4ufVPiRdZ}3S6ng)Su=4mr)=5k+b$!@(P5j0xBGiX_voF4uJ$Lm znlQi!Cn}}lozQ;&LVInv0l7v(l*?KAU1eu42I#e_NWGk?EDEuzI_7>}oO5E*4-Yw@ zWXoL(K^=QtOE&2@pi<>5qI*s6ST{2$T6p%9Lbs7(bggLD+}zjsRQ8_S0=^Wxbbxs& zSoEjSS+|}7Bqv-r#U{c#(6QMu(=pS%wG&$8-JXBFy1!Aew6$E;rM^Xea_9z@S8Fv3hY z&Hcl%l!1I>tTk9{%bz!$nGT%}XBn$ha26st7z$(3hK zcbE1!anaDJp{u`|YO{P@dLgG*X^~hdwj%l{H1D$Hc=3rab3=nT*2Z=bqsA~4fJ2In zd7^HUV+aU3 z;Q&P>Sjvu0kv#$18o6}54JmVc5vC`zts|{c>0<}}ul*M^u!E@4B0cexo_rO`SxWbi z{;)rddN6Q|-@sVMtMCMLq<%huhPkka51A7bYmEceUJ#DfMr!H_#kZWCd&JB_Pm8aO zyJQ2n7%CKZ=!)SjZrejarp+h@tG({fROm2P{I;tYKelZ2eLO0t&#`7c>+E9L@bGqT zj-hKw+$GzwaorQAvfNC=~{y=F#VhM|)RI-U)>hb4PNT7*%jP zr$=_TUWHS?tSP_}$C-|k89LU;!|79h3RKSlT4RV9l8A_@R zPE~1K#EA2F_EAq7BuxX50?zq|B8nza+;{hRY?;(*%@oZxYn$^khmp=q zIi=@~Zp}U&Uv*zvU$Eb4cyr%lI2>L{J{3Ok-7>yG8-o@N*BuvId6dj?iy#I<>X+5j zy%!qVuUB8LiCjAe>-Z8wAXlvJwZQJVDMh6|+wr$%^$F@3F$LiR&ZQIGWdhd7Rz0P&c zw^sdFYhuirqsEv&X4U@%WK05$sI&_$}?ewmT_v&kyV#H&D(ftEu(M7XyC_kPvo|pu7Jm;2OF5Qfz)Q&3PzU{CS1}cuIY?hssdZ3axR+U1@npmgog}EIm6|#* z9?hjAFys(>M|=nDre$CA_S2#no82oR-aL1^+F_~xICLmF#%*Y*-;1J!vOf!@VaBKK z2)=!fbJ^-%S{=;ebAOQ5%)KWH+&iJej|94qa6`ddk6b6I`BdNi!c~OK1 zsUrIOomH0O6!8(Z>L0XKK(yZral4?R=t%cNcy}6M127~!P9q{D9I!{#3E&0?eJK~V zC%h-NKBr&LS!7ak=CD5pw9YWH8Vlaz{5VU!C!@!Q;>_O;JG@_f>`G-iUU#nbGzR+M zu|M3X8(7XtvpqwVP)l#h;^XGKjjo~%AgjJ@)ajgfiFI;{F6`Y07qt`x?{}D1dCWts z{iud7+;r$dcV=J4Y{QJThN^a~zOEiu=d(OWlQ~f<-OAdzhZu<9>(!$*tXN4^0^HPI&?0xb6>RM01K8{ksvF3#5u*pqp^tIYy6yp(Ac+=L= z$9YjuBE{`YN*p(TUnaPd_G1r`dv{b+h&TMFS6Ls8BV-kpT{_J+UBeg>=_r5Gx@=PG z==lgqe=_`=>m1{@C7E=+oMUn{Z2+EGTS;6c^rqd{f;bNwJDhHMJql`JD7jb{`2ecE z^E??HZi;9#c|Rq2xnje-zQ3$VK+=X*O}D|Q#lXhb%5Rsk8NE99l%g=i0Ugg16BgJ( zY2$n~4qepz(!Si#EyJtgjoORd)&Ul!P9sW&w&%K(Bh~j0lciM?a?-KL1{l>WKmDUa zf$TA?k*}|~d0P)JJu`6FaiK=}3KlJUhE0=G_L3V~l^t$uit3qD42R8n?=jmsheV2- zC`1z6ik35XSi6JvmQf$kFH+D7=H{+!BNh8*%YFioZ44jxKNQJQPpFV$5iMMGPkjyZ zR(%Z%X5F8!S~pgh9J~F){lC0__hkTX`@27`yY+; zH>2|Z#&71*mZhX`_EgO}aR$?_fhmQl?h&VHq;LGDVj*E8a}Y4!JKr>)qs*4P1A%^x z{_5!+DTfu9L>%kiu_xN;@901eWkkfF?0{XTo*>fN=y2$<&daH&Z7XGKT!`ne^yTbi z1%s>NzLGzr>u2WV&5h6#haj!({W+RRsB|kE+^5&=<msE)BKM7a9Na+^_l&q;^m`>(wbp4OAfPpZ|5Za$DZL(3v*RR-9Y-{ zumX^t=S{{qYC3NNg^qfbkel>PlC$VZ&b|Drz}&+9J(D%B1{Hc2aA^p(s;2di(BxBK zvQjiN=NovrUu|tHrr)jyfoeVqqaB+fs`*eOrWi`XP26YSnkM|(1PXct$zL>-tWqYe?IHiDRX zTmx9BFVc8pZVLvB3yHF;Y>siAMOk)yOG+>qhP87>aPM&Xo5^VNb{|DJR#!z0>>c%W z`xT1&DJe{#qKp~@140(QWy|BZ*ri>=pzP-FQDw;YW{`T+bhmX^s7g%0_?=!Kk4Agp zUh&l)$L4n0Yi?w$f}dAH=bEN0s%5M4ZSHOR;d{Nwz^~=Px#>79SXdPE7nYP5t?gP_ z&DDcgI8{)F={;ePA0^4@Dkte=tiZ+Fg|M%ab>_3SRb+O=*Hk&g*3Zr>DYm-B+r;}Q z>=x{Y{;qM>ir`*hF{{Px4Ua_Qc^4#NRK3~nWnIXWo? z**e&aRjuBrAF(03GDLI0BVHFd`Dyi5!{_6Ga3VAn?IHfPpFT`McWoG_bV(}~y$Ssh zJ%T1dt<)ms+TlPAEqoHz4GCmSB0LD2^90$}q-%^P2R`hreagJKV}OOhwqtiRc|vV( z^7BPzhjhm;Q~q)2gl)itRrWV!v9@EO!M>?pP*g<97^6Io- zDv{xFqu0)%>)33OBEz;Uzia@op^U3{PH=@n-i18C92-IBdSOJpLd;@U8AQuU z4trt#PJevDp9M=@4kE#gT1*=RqfN3ing&{!kx*{d|E73aSdc{?yEdrd<1zGlYrjcg z#S0g6A&`<9#_2gKSaQo7Ww{WnC_|NPUzs0y+H$?MK6Y5yb-6{8efG8Hh{3ZGVJq1>^fcJ7!94o2G#X#h~fSkg7N5ygDya^6ZOYRZ~08o!Fc~ z+%UvzPQb?2y<%+3v?ibTjXhgm&?sEvwjy09W*R@!bWVk5sYgqr7G4x31bfiBl`KwYO>L^Y;hGq20yR>cw3$MM(R-al@c%n?t_LnpIcLV;SW< zgUzb7Pg7m5Ynf+^XP9THYx{-khil)ZT4xh4o7`CA!D*{#K!s}6!Z~I4?utX7Dt?9~ zsz5*T*0H@nJgJ+z)tR7+r8%V7>zv@ff;6~ z->M&mmz~#hd{3_L@In?tcZ_D?fTpDjj@^QgW}K@$56%Zs+Yc+@fY5K>(_EEUanagt&Fi;h-^rRfqsz%1_?(gcO*RYo-Rs_nf z_liw%WQsP&Zt}hAu7SROOj26QaS9hA#$MuIl+1t^p2^?bA3uq$iE4eb7(gFx9+i}t zl7C3L7cs~@Z{w7xL@ozBhd&`9BQ-YJlf8hkH}W{B86}lrxPn8ah*?u-sHoU5Hz(gj z5yMto$C|{K1O61)6Y7F=FkEG&8or$2?{Ji75vvj*ANw<1Da%MELs9$Zo#o^km!x#8 zKq;G8e%5zc16eY$iJO?$Jn!pTY^)<*9dOlS$Y@&BF{C0 zv)g{A-rHSflzy%RGP%T}ez5QsPO)?QOlea@3Jw+%v#H2TSgT7er#-&H**>vZr$bp? zHg<1gk%8b*m6sh-%SZTb&071Nz=o;Hw#M#&+>fZb0~Xg!yu*&e*a0KU>W-=}FxR)q zYmZYpbrwX~h_$LZ)IHOF2fI4OL+U6R*(ycTHq$|s;!lZ0e5BU9(MUo8 zyyn~C;S>5dTlmO4={E01N6st+{4+X!A9(7~{b#DQo$se6G|gozZi{q?UtH^i`~<$G zrUqY>l5R(RZZ7=xQ?|!vswBnAlOKXs^K>{Y8`fP-LTkUifp2;~QM*N{HD)r&b|>mx zMRR(DIK?LNv_Df={jO%Ir&%{8{82JQ8!TLt@lC6vz4P7r3ge34O0eeiL7rV{|DDTj zfION-&-w?4RAG;>V)>A@2i@ZYxAe#?&ZA(!XkRF+(aY`T{bpreI>HJy;1wXuvcpxWBN%!vqqFA6#t z0Vq-;E=D$bW)2osK*?V#e~ajtnV9Igm{=Lv{}QJrHmXD%?DR|=Oq?8S0L;?BUfjgO z%-orXgNcovlbMkPz-meW7)lExLEFDtiU2D0?iV&-D!BBEmfSYc&n zDUx44h2INuOae|f5pggx(=)MiaB&c^G7@RAv$NB4aWOOfrDgwq|GV>lTCy`S0!(rNT+I3Jq5f0L z@$Uiu+uDEX|5N%OJO8Qu=eYlFqeH~bNu>4fvj#xR{~G$=WjcVk`QOw0ch!HLKPM*_ zV4jQs_xv5;T>QnS|0gc~UnDLI)Bn=P)Jd4I4PrzJ zzVd}3oD&8+WGD;%nNgI?c`sJ%17yfhR%}QsjL_i|6IP-~7jR$4lT(*^te$IGNJ-Gy zD#*@yBa3@rj#n*12LqT}6 zHlvverTyQn*Aqu|H|yF}A0;{C{YI)P+6qT*p0*cKYp8L7)><@rOLH9$8QrmQD=2ax zuto7f1v5f0*SEEqeNc zoY=?0-QxKU7{r7Sjm6LEHbMciPd3|7#^OHUKONfFuRb-2Yew6aitNY^P#t@mB$r zi0Oa$`F{t*f9bIPi_~Ug2k0LG){6fJsm%<~-r@LfQv19U8bE44G5|>J+2(dTx2?@o z=Qg|2L<9*`5D6kM5LTY>VFYLtVBi&z6rxC6!5>Hp(+cYYCU_2L@WlE+X8K7EVt6jv zVn2S&V=IVai-kCU$*H(eGG;vGZu#*)=UfT6l-Xr#+HPo0a=DaW%7B6aWkHcR<8zx| zBfY@2(g1a0DW$^W^I5JBa0oo(nfgL}za-?g?FE{bqM&^q}TcptIx&3-~K0>=j8uarZ z1b9FD$Z_PjivQ5@4uI)gCzLRx`_dn?q%d$1-mgfRPC)uhRyw8n`+nXRWBPCEQi^}_ zJTkOjY?L*f`cZMg$aQ_~^%`Pyakf3h5)#;DR|Nzb1smo16c7PaENT}box_x47xs&U zcjW8|T&Pgk#z;(Lt@R71A36Qw3ny{Fp^ugAzkAYgg(l&?CX|5T=Ap%kNUu(aqO`{F ziA}8ciZX7fvZy1m?Sp^-Ly?>!366&u_D{Ma@k@;;rcRs~0D%*B%QVH4kGllsgS( z%pfX9>)NmfcoFp&j9ebtCr==S8+EX^NV@DqojQ#^`L(6bYOqIZYvc8j@XN)Q#~C7R zT$852`VX)9@H7~gfktSFeh3$~rv6@T{y^fWIA_Ts933h6@+&zb=9)Kubnwk^MFXR5 z+&9<&2YI*sdfRFAJF(lOkXke`1LTz1x+PdfANG_^AcdisX}NNlA>{Os6HF35d?mS< z##ApXsgxbmww+=l*u(2KzxUq(SXzOseJ5!-wg#A=<994mnNf0SK^_n3rAv34w8B{t z)&$#TuNFX6sXj8#3_b4P{gB!stYn>K?nA96|}2M(lf5zek;3%F9i7MOn); zfcBzJUD60G3;IbA=!^C0ywU0|#vkjX2NisxhcZx$?`VW>Kbn!MF9pQOsZOPTRM6pmVEXx?#F~s(bm%W&85a zhM?4?Q@)&VZfKBucF0oJbyheX0}g(Uo{~JK6XxT2lAbZWCow;*Z^!;7y<4j7xtv$Uf|Rd>8liA*`+9JOnWtJoE{u8w!;~{jlkU1n`H`PN1l-2Q50hnsz?c2;P*s6tDvV%!h z3R*D(=tfBE((hCa#rA}fA3n8&W3quX`k3zF3=dqD{wlpz?n~6#t#|UcaiSC6d|WIp z#Fll4{T1>J*%29@$QI%YMYiG_Nv~|YP&^?=idDa6Ko~)5KFS!1n-%?f(2Zf%L7Mv@ z_bK*VwRG zSrVqe>}v8tUi#}4@nB1m&L+(d&--3)v(OJ}+J#Xp2dKfmBWx0vJF`BV%`03Nx-j9r z&A~Awb_&(InA8(CWZNf2P7`3oe!TMW!q)txdI8m;DpO2P`bjU*8SB}BYxzs!8fnub z?LAR9U!FR^ za=XTmDks1@z&FS@Em@hoY4y9&{oAs?zkPkDT~^ATPox>a-8bU?DO>C|8yB285H_F& zKUcSOv|aAa#|!dBhA^8LO>CCPW&Tx3!I7{w;(H7868%`ZcjEn;%qXT#`!0*;zrcQ3;#5=t9iRFPJb|Q0&-n1eV)G?uB?#AsO+k1w`9YtS)do1%iy-Uy!2`*5h z7TPvn9gBJ%x*@o@*U_MGnyQ1WgVLMKngc&F&SoPY}FJ-(E8@7L8_0{=?+7@ihZuW{Z2Sx{Z{MKq? zUjZ<(L6$cboFx1aK3>>XUFxbM==U@lAr!13<=5$cXl;=WJ3rjTp8c`<-?nvTL^}4N ze8jP0w6A&UYLr2dcj(=v)urjfE}R)NG=`F0hKJ1Jw+eKzk zkC)o@ASdmy+0&$dn+(Ox!?U@U+u@)>|1k^hSa(h_HP^bUc}iw37>;OkRW8ntOopi~ za~jOEUvs=>E<=DMbKP}K)$|GEBaQWqAbBu>iwZcku(6S|5hX>6ZMVXh9m<#lEgVvz zU56qm0vS#%Pc=P|+XhndiGCjRBP2d;S9p>O^~DgxGMwkS4gMiG9FG;##2dx3E;V0+ zKu$})$(a0?i@m^|p(Cv(Q+L3cQo~N*yo`L{tG>%AbEN}|H^|wHtwwSO+QlN0);4~&fr91_~zPhTJ-Ma1IXelRD+qdqEk6arRp#toz)E?cr1LqCQP z4QFf1GDaFM%pu?^uKC|f+v>WoOQT`JPK8l6b6X2#MztH**vPTJ&Ci_UmK zKiJGC;|A@aUXj%YBX)r9D@Gb>LwPgX2=ADJE3RKEG`L>{)9tZhN2tfI!k!L{-l>Z~ zml3dqabJhK`L@4YzDUFN_z^y)zcwzOYu;+!1QsIv1|Ke1mvXT<4ZOcZy1RVJy`IWX zHC8$cIx4l6X6ebZ_Xd7s!x(|T%yfhkARItAf%xVw?YVN{yH1!k{xVHeU>Z)Kk_X9# z6bqA{!!?@28Blj#u0_F!lN|~^p(K~KnrE^YE;GS-u;@thwHyIU;l0w6q?jc~wIPov zQ4@BNF!Qljwp$mVDsTQdVr2QV%UAxlsvU3dNqpAk9}C#oc&N=h#K#HjB8~)$*X==K zz&55#E~eoz3BbAXgGrT?*R{FtYN}ADnx76>!D*O4ZCe_ zAFHEItEEPB`^(=g+$`KquSprA2A*_Yp?tAZ`18k|`#)>=B9nO_7AyI=IKmO0eS zW*V*3&SIWo%ec5WdTX07&i;5=^!&823fnGR+98U?D&3nqE?>#m z;Z7@-&Mf7?DFiKWTAa)T+}2fJgEC4L%K!=JpPUzjf?HgQt%(rDc{>oXDn*2`b?I5H z8*6?+ZTp(fN|@AQ^YYYh*0jMEYRr-zw;bC;W0?GfY_uktQj75;j8vHQl*QRvLI&+^ zKC!1Vr`AP5Rt7U)A_=DX z7mz43zl9Oo_|$C7jk}QplM!;?_berABRzsE-B}L}*ceev3vLKbZ$_LUS5KQ7MZ8b( zV3}(dI%rNz(inIn%UK8f$q9=<5sQwdcv&MZuLiD5XxdWZ%sJP$-&Br{EX`0GF_M)R zxiWX0kW(iM;=Er`=Nc#P$a@8(gVNPAkTuyU*lWmpauLOMUQGukzeJDz;1GwIQe}`{ zYa5S#vkB2C6172tz0Ms^_cVG|UWS-yKU2bq12X7c6NUExKo~r3T_#P+-lHT<|o@8#nSma&^_CpRR&c)Xes=! zjf^-CHXav$Fu7vdWb*p(NfO3Deag&Vy<T-=FLm`YUSP=K z-@!pxh_hB{eo{nrR(3~}9II{nGkzoxNE}U*u2nwP%Y01b5%%mIKjmQ_i@E!V3k0Lz z6X81b`yO-TZv}kR-4p2&Za?t*5L(~!QT^CL{7}BnoW2tLLiYsqK~yO8GkA?4 zEqu!_y=Mr=@xg3=pf8B&3YzD+$G2X!l1WxE;o(ANm_XVIgxi@IK|+wzfc0rSc_Z2X zg*D0QIB!dg_$t);b4hucZk^;gqx>jT>v(AG-u-#=Q|IJtIy}cvN_U8|8-e?E=D0Lp zFIZRf6uxNFAL1T&dMm06na>fsAXK-MA%8_ns81Ck#ztf_|5Bh z>|Wz~H~gw}>gJmK6%J9a$Zvn=4l9(=JAi)<4My0HZRvFl?`sD39;NZ2!sNR!(TYo-a$PPnL>jH-Txr5Ye z_{E8>XE_GUNt$k4qnX1u>`@ir4Ap9cBL&YBlEs)%2S!|&-(p(Aq##5zBQ*6+pAoU?!AvO3Ah+w6k2Px`DUM)HT%PQ5kUNl1>gpW0-ncb5)BT_hzx$O7Cai@tphK94EY7ALQ|mti00rn4Ce$oIx1t@Q=SSj`^W> ztaNNbn;izPH#HNg9@$0sT6V0K_XX2Ao_UAv2?NU_T)`WzOE*WA@?hd$z$ax;w8KUm`K6kqzK&O9hSHv;>@G}avju^Gt?vEm4b@jASXEIy@c(&P#|d&Mhpjw-*L#R*aF>3P!en&03~za!03s^l}yX zli!`{-J>>yMp!Xki84 zRDY;QM-~i6{*nhrQ&q+G>uN zyDc75b;(V0Yh#Q_wD`edtob|o8s|BgUSeSoW@1IJ;h~vQ(U+buKb_a>L znvpv-=I-+A$mF#1b;LxM>JKwGct><8uU&4~SACzS?aU{oS*y&vbZcYs#q*p+Uu5oJDH6e?A&X_G|p%Q;h2d)o@jZ=y+oXUqiuI{o>om`cK4oG z{1%}Rl;KI~i5M$OsN8OId>lEdl;dKv)<7-#C1O&jVS;|HAxz^((w<;~Xfjo9{P)1g zz#7d3&l(b2vR2XmPPh8ZyDmCGvA<-&6~78hV56Wn+0jYbMdRq2-&l`5-g2Pe@MbMI zRWJFPdT*vdr9?Y6>bjUtyM^9K%GEx6D4h~I@^}ms&d^!=DRd2=!$b8^Lx4{~*ZC9P z9cS+WpKBa9I&)v}K?+!u6(bIJW*M<+r3wPHMAk^h@;q6FB@?pHCRg@6Frrhvfao{6 zvBd)Ig!wqy`^~#v8Z;#HH}kyq=6I2C+K^Yxd?r>y-XAKA{0$*1Ax&sn1gBPYK@ViI zrwuN~8TfI++z6FZ8r}E3aLL$F#p#Sbl$(mV_zCPo5Hy?YhEjDxhhRuhP6mxpUeo<#Z>968S+KTwD1EOtIohvP}~7$Di-1=zPFR4(oc1-lnI zN9;s~{LZ%fy}!GU=s1WI>y-o{z_+ZB5e+50FHd0C9?RbyVhEWL=|&nWm=h(ms4K96 zGd3_kywCt^7Yi%r6=l#757LY%HVnCplo42zM0TGOdQzw|K%tBw4?~nxR+JaStPiWG z^bco0H&&cG!cZ9_@dHO11S)cAA6dT>@)rzC9)<&jv}hK%8EForl45S3b*xh!f&+b4 z;w#)?4{Onp6E9&2DZRfF(+5aeK+DfPlC<kslesV_Kx|}`5v_x(=%wFw&6Gp@v zl76{u!?d^-JPaaT5KJQ7(HmyhB%EszlXc$>F$2h`llP z#J?m>o0{&||n*BWbHm5!X@e#Gg36AyyM1_mu+7B$ zAkC!wFm5EaJI`3_A##57I^oxL0_L@9gZ5Cbt@<(C zksK)BAsjG=HfphNB-}Y4DBcl#qn^EDy|$72JFlsB3H4!jm9DXN=dRsP;g=y}!u^7) z$^`mY@Nz>a`j7OrPF>syGLZHBFTxpm5&BcNq5D6k1D~1CMR@<*pf86!Q@W$vs66YO zvbn?GsJP?%#yy)Y2R%ca%X~m@?muJjhCH+L#ylgO3wx*T>21e_U-htrU-dPVscnPC zLhiiG13x3_et(D36?sqFBX)$I=yjN7I$)gv)h!$NLO^R&!@-B>aS^A@=RL zf$E5TChv&%gzgIDK#p^K=jjM}X6uM~hVKY+kKPm5W+=nl(Q-$;$-U;^bqiZlQjEN1Csk= zj_~BZ?<-VRV7_E7HLGAw;1W(aV$dd-F?__50}N{(E4S&iS3VzA~tlx*3;#sr}>lEem*Q9!NIA`4#N2jcKCe z>=0i;I1v=H+aF#a&;fnMVdl36@t^2HB%q@3`pi`4`jGAt8W<+&iV@TnI5bQ*Z*oIo z;=3nhPiAhR2y-e8b$ry3D7l!Rfc`0hj8vk9hWdVZP!OaEe~e7W4et!M=ZycX*-L`6 zw5#=}87CFZ&1HWPjz+e{XmmT#{>r-9nLb`y)$Ibn6_lz?NEmk{T%w$VQi`k zx8i~9pbLl3_axx_wKN_zYtS}fY8xksLQNonhJNYq!A^NBW7;rcZhBXcCQ}a0XbO_a z#K+K4RIqJhtxFr7!f48vTkXN6q!BQTu{1yXvP7B&Uzb>KT79GIlO z9Y?NnThpbL4%udWZG;JE!S{hz1*{#?q1!w*b#5aTyL1In zvvvZ$abeno#berBSirJ^4-sTK?67>{+F{ohi-0YY zPJoYrAa3f&0etpu7uNmHk;5BNjgKy#dph2VhXd!hD?3Be*W}pOYAd%iLpb(*9r}-ebCs2bNe-W(2NCCgO^I!h|N^p znw*^5{G74e`}yRYfu}>=CPAa7gJ4~Gc`A>7&II&#Ml2X`P~=A=hfQ-T6tL)!JWk4C zYh!(Kg&BHto z$DRxY;jqC28cpQ3&%X}J89FR22ClM*1F04Qgd%YX&FE>hBgLPi_vnGOWv-ae&lU5W zv9pqPk)UzSfv!%gN)V7|{_EQQ;$#8>DD=hxSD3V;4ADS?xB0XvJ!mww37`5%c1kk7 zji~KQm(36#3VLGi*Mx2VG$?|qy_X4n2z25{k^yMU7TqRGDH$4 z>JHc_WSSJm#0yiO+)0R7i)zVmq%LWH*C!TF%U0Ha=;+>gXeQq0Mal{PBUlp5^Wk)z zz@^{@R#s-N6=3f676=A5Dhjrc+*E^ApJNy#=>x^LzBkFJ6yOOYsl z)YY(%7<$ksYZE-c!QC?_Qp_q0pFD4~z~dD^SU-wlOaGA@+%9SSh9XmszqaD6BDOB* z4*`jG91WtPx>zWtk*aHsEbNd=&^ekXrXhidHB*KARVJ&-tg0Q|ymG5TL8Q#C)?a_dpxi&#(bj*o*ROeE0 zNxY+qWSv}IcecBT)b|-thtu2h^kYS53SrJ{5^IJaCNCa5UcZ(SuuSEd05RHc*BXGn zWeuEPN}ope=kQE#+fXEr;hjJMAKs79I?G-p#61qv1DycQk3lLnf39e08tg2Q5q%ZP z93iN{g09FL*Sek>i{d;~X3^>UG?)%ju-JuL&D}tw-I-=LUxAMo*sID@#pPo1d^}d8 zn)2f>+EjS=RyHC2mV<-%#9Zyxj#@cZ+1(K)xrD3mhcP$JxNgOE*S*Uv@;-@=q@yXx zU)koAF*q_fz+v%?e|}34VX^m7?BH2Rotih4%s`8KFIhJ@?8-L`^hPkCuqQ^y)@t;r zTKde#Tado(4f$D=vcNn>_G0NC5Y!A+%`7I95lo#axsQxeQpWNA#1lqHK+Iilb-379 zi)-$>Gr2t@d#kz$W(@ko);bBYLNQB=SVC~L6iyoP`5SD>`z6d8#bW- zll+lJ>s_pgwtR&g2P`Dbcmyu*gnoCGR7&4h-j*2f^!jYj&srWD`w*SrDt;**3__2} z2PF2E#_G26->W-Sy?*^U2pZE>H1k|Ee7fg>*2fAb$?ya<#Hv)dFkZ@oC_3!$P6@c+ zOXn&&s@k(=I|H4f*)vWnv-QclDY%{(HiWEuDUp*LXj<(x>5P^W4`$NpTLV)qc>)&s zcgG<6sguxOByHk(q$A>z5@_b%HG{$5cMHxm_7D~k*)g-@y0Ka-TX8~G@I3Zu%lSxF z*aw4SHKPX4zsXcnuO@g3>NKHLhmPvJ7I@%Cs-np;Kj6!?33)c@a_}m0VeQbfDD&|JIS}=Hh2-!eK$*3#< zqgt1*@ahMyC%n=cm^q9L?Lx#DAV{&XQ0u_#4WST3nfwXP8=o#=W;KUvR($N^f>t6T zldS$Zu*%T4I+>6oRGryS7%fFdc?Kn~iDBwd2H_2O zaxvSJO_tG9%xl6@<~M_5n@|7vwuYwyg(L&%g0KhYbjIFbySCB$g2l(XL~*5KgDEy+ zo%+|PfPF~#Z6n^aC^_9zG2FT1{UX>m*EJX~^B5iTTy9inog$J;`&#WB%Sb^;ds_9W zVd!=^>PyvmyzW!eb`{0JMy=B$jN@ay<6|$E+%xu_F;}pY)c0h0AZjwz)Z_(nWF1Ly<=afR zc*}a2*}!g2zSwnxB2Qy0w)?XoWhHc6xnII`Q#xdpsV2ft1T9$8dlMgexPE71#Zm)O zZ@L)1*2l0)b;&Iv5fFGGNDmiappp={z#(NW^tRHfSUpND^2AowdydH|5QRDo&snk_ zfgv~185$)cXLnr=X6??^OMc!h$r1!ODwk@~|7(@?|4u3w;^cihR~?%E?__ zxjVj8CbTG5L-u;ur~<2x-xqfB-UFZuCuAF@xY8JTvYds62WHhbWYk^SK$C7>F`@Zy z1s+%_;?F(KE#3_x2s(>5Z*48&I@Yc$Z@s4(wX0Nyw2mrRs!}=W9dys!XKy676SE3| zUE*G#DJNzEHLEdZ_qR%8cc}=#z=cUC?TL(M(KLLCvFyQvfXT7Gf0Tg*29g&wP6OU7 zZbJEpvAZ_u2~;_<2BjjSA;@L|zR(YrYz08ip4g0aDJqRQbfCG-i_C-??XJX1XG5I9 z(NE|z5Dn^mX)xQlm3y}a)9DXyRW~#@uEec2h`n5~wQMd>nhPukp|r;8nU_&d#Wxb7 z$uL?->m>K{2>9C6^5*LrVMEW8mPwCvZV{6#Ad{2_y;4}m^sFg9Me${2j48NB2syr9Qpn+KOUz-?Lh2iQCnicr7`4<`cCaWcO&@EX zr7_zPm;v4jnhdL9Q{(mhIyf+E!#jLU zu{xa4IkJp>f2fPnOY_?tr{N$I@Y+NC=9ql-xDcbJ>zaE;;CXYvQr+=t>GRgmkZCI0 zSs``o#&It5xyRUmVXySfa+ZF64db?7R$fVfjKE~iD4uK29-ZEawPb-yETY0Gy^yJD zl?w;0`kE8xxwn|=#F_mMj95hB_{=aqjyf#^RDl$dNDqi|W8O_`=B4RZ5JoG9fuUYb1$Bo$iq^4*oOr^wc-(466HEl9 z)$;BB)b$R=#-F3X13!nORIzYKHsEoslc0lEcFTdv6|!NHHpVXncc&3t5jSjYh|iwA z{dyMln{4rn40WpT7oY3%@hd)?R&@s`TFWh6Qd`1b|Cl!HINuS<*5v^o{}Qr!^X%2u zCErh0hBmadWveK_NCzGx)3)r@E@qFeRz$6%W@899kU(F;Z``N!O@-WT0X>x+y*Rl1 zrBjRAR`+1(`BanRQNp#7E$t(}?64aRnfR1X-Cpd%KZiQbA1&S;fW#GV&;8=e&6&|U zyDb`-u5ckqwquf%s1=3~8^~ZaZBHzTX_%CV8-);SN|8ZP%(rfE)zgl7YbtBdkG zL&(-`x+jIPK?Y4&Fe=%&>}-CU+?=iHk0t&k(P!XQ+kMT@DNiDY|~= zt*WzmRh_n5A8xEMr$_mIeypw5lDBIDd|pO#f`fW<3We@PVShlPP!@eKNOlFv!$r|F z*gJK;A;**#>mpI%rYU$AqnrOJnaBNtC>&O1PKNnlR2NsxTRCYq4FzhBbBU@DBj9mN zd8BKYS+)(Y`lA96Q*eyhFm7kZ23tY8*s)iZ#cZmPBEX*MYf@^t&9oXIY^rQ0KM^Oe z^KgTGq49X6cMWAkFzJc2D#0w6R>7)A4P1d&^k?Y~DBNta8Qr^4j3r-LX#6E(Xm~O3 z;!7PTB~eR9uzgcdIiGaxiLElqVu&}_%(6MMcZ+Hr1?k>FMI-m_YCDv48=Y38(~_Yw z4DDiY3Rm@mJ6{S@jEqbwTL?ia{KTP4ho>p%YH^p{_47~BcnaGURu78}Kd~1lv9T2N zxZ*x8AMsXI{jRNUVW!>v`bB%aQnU9sJ+Gq5LergBAcx2#yNE2uKGGKOYW*quop(xT ze}o8ulyRJiTU%>oyNBG`TdEHhe^inw&d&#F1!dQ#pCnWEQ`gG|4|mlGbu_Jb^pvR) zQpp2{xI;Wu(7EYYe( zpV@EKGgU1bH1JehypdM8Q)bAtGw10v;G(Sj9KT8OphUUU3@`uINCambII&dY3_K&d z5I&^i{<_ZT^vmwne|Q+N+w$dkxrjN^W$~LVx0=fAELpmS-&3{SbUcU*3(hK7JKT7i zgnY_zvr;(nvC5GKCiYtT3W&~idQed^tL%CevD^<;=(cFNZO&{cC6cZemY2TTfM!Qa zrou&NW{9y)gW(dLOPGYDpQRWjh|%Jw%^9QONSzRhow?tE)`KFo>Aje#7o(lHz&J54q9bHYju2H~NH+H(9fr2*xT^0sDJi(qP*n&euaZ2s+<+v&8v{;eMYL`(y` zVgbAmdgrkHM_(0@L4_j0+Dq-o8fFcR(O7RhGr!;PyEIPYN6ppJ=9|&l<5iL9@0x}P z!>;MoR(ZGUd8OP3hB#`z7r}@~-2fK8h~t$UiJ80LJ3d&DhQieU4^u#_zXUE1tqWWi zy2JBu;K{&WJ%{ygb!Q*XJ)SKdp;ysNnHI7&I*PL8i|Df6DKyGDl`Y6Y_DJ&DXtoa1 zInAsQ;jD~>v*HuZ?ybYSNEMhf*=9D(EZdyTHlsBnlmz#k)XDv`A9~3pl&g#`^g_%Os~a#Y4?gk85ds+0ma8* z=Z7>g!iB`mrDxF=&t=ocT|T-8>9KpkjuXW2%=#mjUh?<*AAN_u_~6oun;yRG^83g* z?UD=5T=CW-)i-fIQQrE1Xm=z(PJW&IG`a1uJwnBuJNDhR?(xT&lq@0liM>RbpQaB@ z6iPA?4Mr#sNP$2N1)?Yy;Bvi*9-x%&ksx3ser3{RerS?DEUjC7q#CV`YTWt}w0Z4Z zQ$)HmgES)cI?+>jj(Opn&8>HCX12j1_(<$6vY(NioKPF+dJ)Z1g62KlO((P8A*GX> zqy!p5qd_906K;4!enc09Y8e8GE)nTM1ADr5xDIWA>XAplUm7@q&KJ;l12QMbgmh>B z#NH>m3*zff&y-^Iew7#OvW`wDS5n zZQwMq+BCic`MNnne8=?!W%btbC6q6R630@lt2SGiW1Oa~5jJSgOV7xAwWFF@k!s0A zI$E1!Zq&X}zp;E{HHxZe5v_vRWRye^H{FVCFsMi?vT7gztj9Kf!loNk7iLjGU}3XUFm|+fK>R=yHi$%QAtYfQ zt?o5^pb8sQqO!PVGaN9`6@~@_HT=r<#+yFA9{JJZKOatQz^@%S0=|CLfg}A6A;aN6 zb_yOxJ9l*#9}l_iLH=8+T+=Mt1jVo`brj9)@0di^ zk|m4lI$X!lMM*h{3K78>5!h=8ftLS?*1Y#f>z((#P5yrSki1~IwCjf<-AmU6Fu`_E?91@)vJug~syxJ(w4O}QKGS-`~lCCn# zg&w2eD=ZFqa*bKLvTb+8w`4hd3uSaVLdC^JMG(vl;Yf!=Av-9jwUhh~UsegSRV86j znQai0Rc5~7@^d&*z;wLqVEUc?JsG0HS|xMNkzI_ddAJ#x|^ij_u5 zq%3^~7mK30DywALm(d$(Z1aot=gnTVep169)+K*M`mF4E#)u(T-jjTnEI21NaB{El zx2#KUk#^PYoORA`$_t-tn7wscH({*ZbKc0|3yY55YfyX6A2N11Ka)Ez^{KQ>dJXyD ztL-!Byj)7sbISYrSz;=qbSSgTK+U)`w*jus-2it;j|dN1b_&gwXDzS5q1c-v4&(}W5R;_zbe@{mFvOzBKCmed13{=wcVAn!6P`p_VKKb3uw~4$=$BZP* zPd|;EF^wkv_R7aoI74%l8VKiVd^|L6uWQ^M(Ee?P{%4kax--s|yt9BvmyelLiWWe%MSk<0HP-#;?>irS_1XI*mR{#D7Xr0T{8yA2+B>-lGG zNxmfQa_63TZt}pshmy&Mrg4A{ok-=Xim6gDWoXu_di57 z_$Fh>42pqqTdC%#FpL+@&`r99ngSNlNYjfOS7)5VjQ<1WU^I51CDh($XLvF*tRu6E zqHg4|LqF0C-MZqSxFZ>VznFjG9wC0>&%)Kxt}V%ak0vc!utjL7h^w%NMz}xGhxc&3 zfwXlJJ9w8)bu*;_^Z%z_vF!!r%Rlc*@<)9#^`6pUpAMzZJeXDaul?C9ym#Ug+Sodp z^`+OA*7KPDS%CUyC+eR9a#kXcYASlJc1(X{@XHXqn+i6i(ykq=$G1F=Lm?^5 z5ffK6Cce`#`C~KAK1J1x)at&?jD^MrgPo?gohsmfU_5=UUd2v= zP<{r9(VSo)=no3A8q*5gv2aW&5M$8-pCvZ}9-A|Qg6eO1&A!Lk1 zAYWjg)9~GFoV|UoZZip(XrYbSy}*8og7bI{T_|ce_KAqgA)=0}v0+!T8}a_)|WtDd?j(sMPTH(qhHFYWgzX+5~4ekVEStv5)0^X!(JyDn-N zIp*q7Yc}mme%CO)lGxc??m<|Id?}E;grD+Z6gW}?Kan+LjLq-)JRwJYpFUfn5*u29 zBW53OW&~y*Pw?SqEKS)P(rrEa@HeH~$}7@gN!N7PsVE&r3({e3C>{C&={Kvz7Og^; zHb{?4$Pj2bu7`V}5yVnRz-agYj)LUSF>wP3Qu=(INrEpUAzx%A z#W!kC(whUP)HF4qZCO{lcu93@o9)I9-ue2Ib>;SQ`<|zmafTzu?6G1TISH;zsDz3_ zNCHJ?#wdL#5i!v8FbbR}1wJUkzpb3U{gI-Ve@f9Gu1o78Cb3LrH$FvQ#nyeZh0W}3 z0J06+rwQJKsuY{C0hD9*pj^R0;c7#%TI^h=aI}z+*vsKgj8YveTe7Kw5eQX`W-BO0 zYBI~L2WE}68h5@w>|mwL8nAaEnZA9O?c0gwQ$EyS$9Dbp?$us-WiQ)U#pCJmh3tnL zVFRBanWMl_CH-6U zIf)fOZHkNLDB?2p8ud9GN_Dt8+$I!>1(wd%8sThlndM^ZYKvl~l2T>qVI4(B2!jj> zWu#?*)pQ%ZUD#;YsB9Jh z;fGhC+ZJg=YoQaL(4}cogM^YtH*d4|Mp5$P-s)IgwXc=2CErNs-g8@RcCgYT)1ukW^6O)NF@2JH16 zkt%EF2!9K{fjC77Cd(-p79of#~yV+SU{#2F17Z;wh6u}AGBO6<3hd~$YI zkH0&aN~GP%iH|31q+Q3qzH!*-JB1TJ3=v;E-d#L+TxZgC7g~#9ww{wGGw;Qb)jr$K z-+P()S0+w(h2m2^{AimU_aUX=ZdW%bxbIb{K@b$9NU71FhyqujOj~3ZM3#~;@+4iB zrL0Di82@usC#6LbZNfy1%SWAVCc1gFd762Vxxp-%l{N!HaW`u8jeF=I*m z*yJ?zK1p@P>*CdXl5tnfRc3l6O${i@nbujNam)= zTqNC${BEl|GymC7Zn$u!S)iPt>cqLf>sf*BdiF#TCw!&20w=rScmw-?-q6;0PkJ4! zkV8C)5dj-^YF!wfQ-c z`{uhOXZhzhzMOoMzCad`yPrxv_?Hio_ilfVO#XfHpUDHHg5+!?=3ga0N$<+UR+KXf z_~2+FG|N8UMMr2OTxV-%yF{}ZLX8MsU)qLtWQX*WFE)1YSI04hjjo-4Fu;!)6fLu$ z97~k2o+|-8K=5C{XW>I;;X`KOLuUD(+TTCkQ}|C_zuS)<7N>_cGpyN7MQe5Xe1UJa zLb$!9k%%4XwtW^Yx@qM3H`RWbd_K8`T>9iab!T?FI(e0|Kpkqjry zSpo<4qiv2r1%^krnqsJTY zhrF!CnH@RqIoKq4y%5RcY~l0SY*r&ZV&fiV)_h^2O0gjgJv8I|O%vmCsCHN=FecC@Xp&SXv8Nv*)URWxM z1%=&(s^CCjxZ%v)!QnyqLkhZBOWN>=K$PV(TGk)lWAlT*+68{LK+j+ z681>;Xl(Hr#_Vf1V^&6uZLhYCF(@KMY`L>qDf?RCSR%~oEDDrG(l1%LG)DMaH5>sF zb1T8g%-Dq896z^h0a+SqUB|o^RfIw{tBCacb7T2bi2GB(aVKO#X&}bB&#c~qr3RqsrM6pnd>hD zN15;N4IS}x_LFzMI9q6B9;!Rc^k90)JY|p0-x9hbcIr&# ziffZOl4Z-5AHKoo--ni59*%&Es0mZdRwLFZ&nu#bai<5(;tH|1GDJK>S!Vl<^qI|| z0=2WxlVzhTyK=a)T#3ZDJ6P{sF`Bi^X`5wEwaf|C!9*9nQ?1iIME8vL&}p7Uo(7NL z`3VDqpH^kJ4JJMFX<>R9F=hGJ)V7S6#LRv*y^NUJmJw5(o0;eB%Siedc%+7Q+R2v2 zk@R2p#G#Iq+cSn+cQl04A5hrEX-~~e9)JDiDQ=RW# zDlJtnb=xF2J2Y@8$iGx!mPJ42m`0k1cp^*53+po5C&MxOwQjM<^HcQbx} z3%PD<+T5rM_(!(lPQ5kYZ}puuc-El9Z8k=BpU%t+_8v6raZfk$K-iF(FJ8t8f947WsF}=4hz{Fy{w+Hq=hG$L!teCP*O-Kp$S0~7`OX{F) z8+Ve_lX55D%9lGG7&yyuJI~&&5^_)S(q})&5A-wT$Mx=b9*QH%D;M@)M7l7CDNXJxQg|Q|W2! zY3XI{?x=K{98TR4sc65+Cv&ki=I9~z zQhJ$Ljl-1jVx2O@JlQ(lF`LX1=PC2ebFH%+7mAlC%+R>Vagp;Hajjvk=@zj?dBX9G z_`LF__?Ggv^$o|T;%CZd*29j@GXJX?)s8E>hoM^I>Ft|)?l3x?BXwOELzS?ms{(~L7hEoMP=n#@Gj zsMBb2I(0C*0E_~)Saelzsj6Ty8U=w;r^TYGpp?3a8wEmF6Dn0($kZov(+1OClVEBg zE!(HkO_Wlk5+=Dhp^erKXo7}?5+)t|F85QBX(%W0vyL$_sq=l}KT>z34hb$Pb*G5R zYUvcIVBgB3v)Py+R4e;V4$^|Kua;X0>AhYXOLLRl%#JqvRfL)2zMLutd*_-{O0lmfQ@m4z>9&aB7cSzNOh?JQfmvnJposKHA znj7guAU9HNHZh7aN_BcM&FRH7Mp2|r6|$414)+fKYVMR1Ql36fLnJ{;-hPHvzl=?Mf3@up9=IlN5NK22DW5d8=O10&n%`nVLnmFSIx*a^Xb!lx9QO0D7? zGDn_ceqR<>=e#VXK!0ImXxPrS(iGL)+sMYM#7!6@WqZc)H zkbM-Rs76)Xl{yAO>KOk{jT_5^??R16WNQUIGV=Rd{cM9-`;$zTwdmUU%1(Q?zW4=+ zj2=AT91{Gf^$EH_7?~V$*=6+`$m1urwf>6f?CX+qsgK*bLlSXOh!d(wavTf}95;jf zm?#wx;2)}h!rlQhUhck*T>tjl$+?Cxw|xKh zE$m5!$+@JNKdE2BD@t*LtO+!ZMuIF!ggzz;1qSvuDq-SJd(?O*`_SyzPd$P}x|iFd z-6NzqS^xIioUuKyi_!xVXyF!(Exvt9W>Eou#gLo@H+Fw61F{ z*A(61xij#v#oa0UDM=y!%UeeM=KpEzOW>oZvc2opzAxR?dnesVx|5KO1W1PvjHX;z z6xl>jmMAWuY(fwa6$Qoxw^7D<4mumSjQb1$A|UD`GlRTw;R8oxo;V2ej1D?7=5rXH z0_lABo~jBRocaB}ELEqgm#V(^+_V2r#a^o38hgEZS8Q+fA47+##f!s;R3Ve%b$)Un zaHdSGfoP!dgi1wH(Ohj!zKLzBy@VZIJ4KwDn=Q`CEmPO1Z>!&F-{q{vypCA2E|ZT8 zDYK*33|KgT9+0flTl7cu^?I+)t=Bi|U+awCR|u!89*X@-AJ=}|DI*w09ST}?o)o<5 zl|&}!5RupQBooQq+v(|!UgZ!pSh{jh z<;F^`iG;6+r&_ta_kd3vhqz_s;3kOMmsaElHFY-88=6oP0SPSn~a;oH^)0u zAE^f;2V?&e{3`NQ?9-AXsoqp9&D9xo_8_jsaJb8i3EXV%V97t(lcs8hbe5;7L=r1f zIh53us2>T7`hE|o&2zHA+?jm}G8IResjO01w-!l(6{AGGMC}PbhT9D+s`$`&g#gmX zT$3ZtBr^BP5-e%~J`U_+)l&gj94xE{)=d$Ci(c<~Xp9TL&eC)zLTk|m)Q-9ln?fyU zJYo=Wp~<>IWKES24oARx2z+G}AgqUg^@#P@L3kTp8YY*AqEJKvg@hS+24f&1J1Yl4#l=i~ zS!<~c)Dfy1`$TZ7n!amH;!F1#(jW{8ykcZ@5#(}t0-`_1eX06)XEpFrM#-hHd4l~> zN6%rS%K-z=0XuFem|+fZgahm_8kissOmImu1nd?9)(e5W3uX2SC?&KAw4g&qOeSv= zKsyO;uL*dyFgTIl)fZ558RU$BYh65MQpFf>LJ@I7@w1DMlX}p_eqoT+RA;t!;Xere zVOH`nD=0$b7iHz48A4xxkMI=Jys6~t-yAIb@8T~W`1PMt8)GY{-T%_F_so3+-5c4q z7nLCS6-2Mz_*7!v{NI0Y;CDa3GG`>_rNeHuFWTv>kZD%SYI*Hqjcc$Ql2_7K$d}ub zk~h*faI>WA?U~8W)PC;6;Gx)O!O!fkBY%s12C^lbO6B52AdQI==_CxKGupuLaJoSo zLyyo#+Lt7+l&5GnYM=3c4WC5EbrXdcT`@`TdquD)EOeNDLg(9UAav@u+S^8gg?d$j8F>e2lSp$>aHu` z889S-IPgrYG(Vw8(hz3{f@gig1r9bt&=^ac<}NR;M*h!;8d7gi)<6^+)@&|kV6lUW zK}*AC?OOTa(z*NZp81oyEj{U1mM;6%3wJDk>b_q-eCnC?h?J`raJ2ZqN6Coc$$jbD(Q7?=^eJb7(kLHyd}a(;Q}1brfEQek9hk;sHF30*Sb zq_NiAVA7_^CX%v1?Vw*GtHhV=oeoTui5K+aK`a&`ZkGD2W+q_PL>%m~{uzRrnh%`T zh+#)Y9-LXJswUsAAuXOFMPb>>JlSs}W>5;H!bCUB02EZcD@?trTHpgSBRH9wyg%3O zs&^$ox@g{$Fz>FcNWzSVVfOL7_t!A3ImpCy;bWKwPJq)pwhxYjpKt*=%{^_+5Wxue z)#1dlS?r4iH!E%nWe{OSWtCvuFjw!W{rhWQ6uw6GpFc!8I(<~$eDC!S_Z*}rs>7x{ zu;N8DCGt!MN?{$UqUypYh40Mt#vM1I$M3u7rss&x31W6w#eG0U&;X~@mXHyviw%l7 zu|=_;sXy0V)Wo<}t+mHGV{D8Js}oPy>Q7 zU`ABe#AGRkehfhs$(F&x@=#5ZOQ!N`DHLWw)XUcH{PSq+Y6Ia$wCt>^i}!JC-}v>bj?-XGW9d zR%zO%#Y+M&V!PLr0tw3EjReAeWzFi$L!#e4TMKYh4uUVh}2fnUfYXI}U4>DhSYU09gNe2G_HDOH2sa%L(DXV)rO z`!Z#O%}XV*l3JzGuB~WNhT4}ZBkd`|Rmx4uN%@~4ePBgx)%g|YS6x=Mwsu3UFtlvw zfR@^k%E+=21Fk5$V!#~X`m*Z>%&c8id$8(g+21R^uCgLwKD3?Q)KQ%b3ZRP3G&Kkm z@hYm5+J~La?ev|F$t9D9Jfb|Q%HdFbw!XL_$u~X%>074?S|Vhl(R~qQMx4mZ$f^ii zi>HL1Tno}T0@66rCygT@jU!=rjs*HZ8k1M?5<@XBJCn5Ye!FPY`5#mxrM1a`PW;ScOMOIXn0gRW3@7Na+an#vvzH zS&T28y-^u*(ULpwkLqYy`^VikzyHHGZhvmp#~c3h%O{_^bHxk4zJ2)%SH&l0huko& zvHc;`eCP>;9)4og>ABzTUH&pt^M2>f_kO?o_hi+sp(y4k6^i7cQ3*I+ zS+;>0!R*jjI24M+@)6NeEt}yGWh6PlR%F%JxvD?i0Gp|SP*_%S>WAigCDbXQFeu!x z1E7Rz*xF=bCE~$a08apGUW${~NnT)^$FCw24f$6EaMZHbMC-&>D7G92iL(Luq51Z3 zcbHxj-VkmN_lDUpZNpUCFr_w3zMXZe&rEz(-K2L}nj$x!WuZ{U3r?MMA|NeX*Fq#0 z(^rFb()9x<8pHz)ZpXOLs0qujn6~$uecz*`)@jR{%Kw?-RCv;vHvO2FOkS1aY zL6OkYYAQ$iGS$1TK{y<;DlC|KK4h)wxT|y7Z^m>ioj2i!&Dan4=CRgif8KKq{nVN} zCOvXz&+Aw^+>a->nN(9#0(#zw(ejz3mIu?5z4+p3KiF{EZ*}1kEO^}U6WnEW~CTI4hpM~jXWpaKN6b0)m3f4~w!*$Ap71(j&*-Wsw z8QP`bsdlpo9?ZOTadD`+|4*=?KE&YpzQ3cRgZ?A{q{}89?Vc zi`}%OThOh#$y?oxOPxtky3Vi)Tg^T0I>xY7VXMKG<+9wlY&~}$$3;Yr6IhmJxgdo! zg=TD(wKzq9A+7X>RN;lBWvs=TIugNBP|M2lS_P$)7G=D`kTPtikqn_%mJN=z0x=z> z6ufB2MsD*Vl42&EKMDz)km=%Lv+&rukw~vrVgE_}f;ipNAq5Xq9 z!84MNT6C+}WS@|Hg7Lav@RKJqx5{*YPX{5S-@PSJMMC`D9e5w$-~eRax}AIQ5uRl^ zmT#0s;aTO+k*|_(WtPeZnNNA)IUZH;l|oi*;)h8s+IVd$JC(mmm@3`L-o`yC?dJc; z9^kw9FNFW)zY{|NS>_mqrFmW;H{X>xNffgJZwms?uxyr-ZH|*=yx3R~;f2JJRI{Q` zGP@laj>NGLiY*t(qY-KFg-y2m?GkF%n8i_b{{+)ky6ycD>#HM~*DjmNZFXNl7zL zGGrx9c(;FZ8g`q?ye>yj_}xZ%2{yjBb8{Kg7;g@f-6xyPCf?n_BNcX=6u)qsIQisM zfkP}3?Jz!@Z8yV)6bx>Tk~e>~DdD~xwN7;-n`cUb+*)JHO^pdy*r1obD9lAWKPf!5 zlG}0m4b)y()^h`$y1g(R^Zwm<0W<4|>2!EG*6tO@!_f47YU z2eKZJH;uzw1Wvxe-47bTGCrWse! zlTQMLAHr7ldJ1(?-Q>3GXSDveXS9Avk=A$F%JmOK&pGf5fqHxW(jZUxQ{&kF!k zlRlB~iMUUwenpYy6S_|rJ`wb-che^VK4JMp&^H22p9uJbjmKdg@G|7jE*)1TxA|5m4eOa_NyCF+wvF_2cYb|84 z5WI;(;0CfG5WKOWy@%Jg3sW?Na6t7~kO#5+;^?A44r+Buqhe7>Eih{|yEcImaDqhN z2@-IE1PLNq4zliiM%Z#i4Dx^Zf7MT(-=t;M)= z^0)^o3)&V_#I41a%vjQe!ip5b5OviKR@$nSKmje}8?JuD;oq4#q>~%e9!8*v4%oHe z`W9QbPYro)?y_~MyWaWbOIs>toWJNlI z+p~_|ynOkDpZ=)lBhR1t9IvD>+T;W|h7Zy&nA^=ynZE|RnG->tC3>pyn^`J<3+$nb)Wo+PO6Z4KagmFEQx2 zb<~+fs2DsE5agITiXSab;irl>@^eHnZw?O(4>v?dm}3HC!Xu(HxEa#rW^14|e0g*M zw?MkVTo70gz9D)m3Q0VtO=qs)u8^mz^O;%PEP1{vN0O{yVL??~n|a)?*8J89f-9Oy zK!hU!tRwWb`V}D3?B!DYq!BhB z@`?o{NQr43*u`}Ybk|YHP^wM>W6&#uf>aKb1nz(^q$fW>T9P)`c&UVRX; zEDn5J{Okj7eT>3){OzH`g=4R6UUT2(E%&b3Ob1cbBg+bZ>DlwQAD~jCz4z{W@4xl# zJNRPP6y~sHm@5KQDf)@CL^aPb&ojrEY)iU5O{dZW)QXZJp&=y~mMluIO^d@L!xNWA zE=^1or>ip}GZJ&fdFmWmD0(RVL1~xWReB`dn+{j7IWre(V27I{*-Oo7 z=4Z;^N(!c8=}b6D5~X}NsVkHo^BE%MGepdTf?_JOPe!Kf$TQ_tGMfgrNIPDI?dNWl zj2!hVZhcRo4kSv=Vhy`J*tyExP6g*_>fgfft6IL1t4mBE%m*s~O7+<>sB(HHhKAna*C*wfhV z)-#jGWHt=9hYs()ycHze60gg8ao_dK_wr4}`Ns^%8;EZT5Z@HSu8-zsA4*Ekj%<2? z&7!ELAJaVE{Qaq=+K}ZXB8Pf`%zoLX+M0Ef-zm;lo{#_ZLT<1nk&y$=BjhGj>?WIgMd;p1BPa% z$y1dZDsQM>Qn4hnD)VFc=jvnC>uMh#^sM}%`b^cc)mtjxsti~A9z?lMRQN>3C%o^= z`(J_gzZCC(O`f<&pE!ZirfFhTR+ZU!x-!Hn154s0#Zexsg#>Y|B{n{GO>ARqZ;Ur$ zso28U;TW5WJsP89Z(A&M28* zLYE{%0_#?2LDcbcKeG6_6C`ZJCI>31IErUtPB5AuLf+m0xvi+XC95?C_n(NR$vb0d z@~#-fSYnVpB+ufx-$75Ogx+tqLS!magFooiWYfMHR71{5-e2Rx4QqUvQsZJ8fH=OD zd`e9muAr={CO>mX=McJO$f_aq5RzWaP*K-40e(-rgHHpKz&8SJNs((y0~e+<251)p zuH8s`!tJC}2_g^LCwTc4D5EvX5BmY2*kCUkiltC-dn~MkbH^5s^NYZ8xi*p$EplXz zk&1~NY1iKdC1AuKCnzei>uanMaqU#6>YUOF&aSPr%zzm*8NOUgCn%{}NFeSUyeYNu z!!o@hL6ui%syIMSpz10~=5uU%$TC$ejvsHj&EM@S=P3X6nQ!dii)uu;1~Xcsz#eF6_~a}RfZ z9GDe4QA073>#2E!heSUKyhqGsVnUJ7t7kR4&VaCko=Zj1&`qT8+?|9PmoC8NaOgy7{&D+_UA?SA)6g(x=v&=g)eY zzW!k(%rE@#;hrClt&NkY8kW^Z*h+j6cfUr(Ns&P)lBd(bFo7d?JF$SB&jnFN42D${ z3@ccHS$O=Y`mpbphJ7O=+~=2uv(X4~AmiYjM!+wP1R!)ec$bLl`0h1H8*+fvhiY$ zv!<>Y8i7HPR%6)pWYq+viI$rksHs`)f*ri7n5s%h3PfNjLV|#4S@Gf3&x|*f4#m28 z;>1VJ?f7}e=mp~&ZlNFR+494|qb5#z^nSYO)ImI>ags;HGb+VbJGjW>omfU1@%t`&maC~sxltZZ zIkLn#fpDI~gOm4f6@$MI`RWw$a~uO8g%oH8G8W_*cpzj{;3&;;szPdf59RRK;Qu|j zJvpk5z~Y*qFSaa*VpfuENs=jsrn4@}jgw_;9Rg&H7i5W{5Lc%nwOn)@M_NU0ZiEuA zI@~Ib<}l?*Y1%>M%9np6YuK$2jYp4lwYudtO?|lptEqoK83H=+>Wk0(P_1X$ zO#8U8U_C;=Da`-Ru52or`|7pA&1_}QJvT1AVi|ou$pyNIlx>*P0^BtOpXPCz>(@i- zy+n00C?p&U@k`E4zCsl(Qxtgr(uJ*zl#Z|-s{|T}034!-Q$R2vd zWp)#AW<2Yq$xfe%o)z7KE8uq&5&NES+fB@oL4n<)>R2`u2N`~;SFHmYF<$n>Sw zbn6j|A>RkQ`6GUI`G{XM*X>BDvb>oraZ`WJwp1q1@~RZ%6H+X|u@uWIlA?I=8!dP*Pa*;90x->A|xI8dVxIw%za2tQSuta=~ z-(hSG{F6T=RV!9CRjpO&)kamI&K^cJ25uGa6Q5w#sn4Sq=oggd)K{sk{0{vO>;e8G z=_q^D_-o)ee^N>+(4azvt;xG!2-li}sGGO86S8iw0m>2uF)J8ZorEWJfzgnf)wcH@ za2knD(C`wiff$5_>>w{IR;8S?u3#^hXIS&C71o26Y{@KMuw**ii8&hwTbDat=VIl} zF7oSId-yNm*bLxf1x}J>5wo*wTBLk*%odIcV59XCXSQtU>EBy|m=>%+Ajb(d#|b)~ z=d7mNnx>1`Nzcimjo(f{vz|DiXe0z!(XdoqgUbtGJxY2=68RD^NRJrVK4EHTrba5B z8Erdy-jUPeWwcOUNw8D&WJelrp@r5;i@?4oJBrDnnULFJumpPkRdgbFVm8>pv9ZTn zTcg;H#eYN+wMPFnVAc~&7Ht1N@Unt#Hj{rslm9X8sYzFLXlXS~ztMXH`#MJ`y?0*+ zHONTgb$q0+bN>$MNrzctWA)#87WZw;Qo zbGbP2GtZAC@6ZR+Kllo7MPOg*h6y7x?!wEOV znV=NX;${OHuB=9nC}LgUN_MI+Rk=!Ehn|q1P`1(A)jufj=pd;8#Ic?u#5f&D=$okH>?3 ziM3*vcNa5I%vdj*pP9#xeGeQvFxToaeXDmT8G?-kKd>PlO@Lcf zN}AO2NE3tq$>YssO(t|p2sNSdvL?w%`dw;rQz5GXIe7ArfKnqw!#9%5J5z-WbWh>Q zzdSQAS)1MRr^1iWLx&CyFML5)qr!Ki23=Txs-X7#A9U%|LMzewWrc~%-!Uh}>3P_n zj=F_yF7g2U0oWR>mwG+!)VU#lNW8*Ubzk8o0g9@ET(dpU$Bb$*GnUA|!OtvG7hW6D@vE`BH;-4lHh!6Qn{~T=d+1*6 zLF?hb!@&paC*&8DH_X?q9rl;9-EdGzCRpQQ;~s-CVttqI#@hmY zJrWuXLp8B%$L3(n4hFLU*~SkH6$|gIBHM~02MMH5;mHS3Ni#{;C3hz2?dZa-1}djUBxLdwjFyvD2dU##W`f!anC}a>)De&h-O`ar zufT#F4_*)H1CP0tbSI3O$Gc+Wo{h)iQS%s3RFpWPKI@9bwJC&mJv8^2b{$K{D3*?| zW8eKKrSu*}#j?@v{bXxnlU&}|q?7i5p(e{~s5F(hQWQ2!Jw7cmPjkU4w;r_-`WblU zDY=hdMfpnm+}h^R5v!6@3JZRBC|91!ecDl&e?ex@iYfWRjW3$jnZ!J!gstv*a_Q<7 z%jkKh{;=`Fsgp=-eiHK!dK&iurBD&-znvNDV;f`i*TUC9`mk^~NbeQ)2I-x`&LF)} z*chbO3+sdQqr#&>`Yz$FAbmi=w>VgY}mBOO}BcR|gyII%NW~_*vNIb7EMZz$#nMPDI!#qkOIu>nv-ib~X)14c%sUwMYYBQ=Wof*!}c4I}ljGY&?oTkN)JBqEzW zA{+_Q`-FW#x>M*3((OWfkbYWtI!HezJQk#XAp9UmFA^37=~?0|o1P?2@LsFefRE!tOm9QgmaUp%GG3;HMrc>A4H{FDn$b zZYva)?O)jXo9hm&Tle90zhO=;-oF?hL-e*=z1>+zR8bfJU_}SV2@RtlGV2zKSu)-2 z+@&F{$TiE|8xGC|2}>p$;bP9$CEDW_V4f;NFO~mV(yyWb#$O}cgTgW zft%+}es%FbG0)4HJp{Q^b|-%Yu&%=Z*1xt_Sx{C%^kf9^NdM4Y!@It{>*T-E2nmo z)zNgtK-hm`xr!{K6C$BrhXU z--%g7;>4_k?fwoi%ThQXni_ABh}q_ec_EGE>Re*B=Mq&<EYXh zkEYI5Y}sJQYBrlKdC7_Qq9>VIgPo82So5W%o^Cd6D5r>TFN+5YLVVsRt|lA6}T1QdE1rV{+^3#S0=kgEjBZM7_#w ztPgMF+^%+8`f9Iz_|kmQG~)BFX-`J`&Z?XzaXsfw*TopMb9dFO7A>2mhFya`y(xC< zZQ9%B`@A76+h|hPx9kDzxhMFVxm3H~~ zeTf)5p5g7=>gLH8yHvb?W(rg-Re4lI))-2Nr$nr}Vr|_^t;*B5#ZaOxi_;k0#e{0# z;o$0vZ(DBN?_P1LuZH1LlhHNaZWd6h^ARe5hF Date: Wed, 25 Oct 2023 20:33:08 +0000 Subject: [PATCH 07/93] Add files via upload --- SCRIP_WIN_CP.ps1 | 55 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 55 insertions(+) create mode 100644 SCRIP_WIN_CP.ps1 diff --git a/SCRIP_WIN_CP.ps1 b/SCRIP_WIN_CP.ps1 new file mode 100644 index 0000000..1c591dc --- /dev/null +++ b/SCRIP_WIN_CP.ps1 @@ -0,0 +1,55 @@ +net accounts /minpwlen:10 +net accounts /minpwage:10 +net accounts /maxpwage:90 +net accounts /lockoutduration:30 +net accounts /lockoutthreshold:10 +net accounts /uniquepw:24 +net accounts /passwordmustmeetcomplexityrequirements:Enabled +net accounts /enforcepasswordhistory:5 + +stop-service remoteregistry +stop-service SSDPSRV +stop-service TermService +stop-service UmRdpService +stop-service upnphost +stop-service FTPSVC + +Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True + +Set-Service -Name remoteregistry -Status stopped -StartupType disabled +Set-Service -Name SSDPSRV -Status stopped -StartupType disabled +Set-Service -Name TermService -Status stopped -StartupType disabled +Set-Service -Name UmRdpService -Status stopped -StartupType disabled +Set-Service -Name upnhost -Status stopped -StartupType disabled +Set-Service -Name FTPSVC -Status stopped -StartupType disabled + +Auditpol /get /category:* +Auditpol /set /category:"Detailed Tracking" /success:enable /failure:enable +Auditpol /set /category:"Logon/Logoff" /success:enable /failure:enable +Auditpol /set /category:"Policy Change" /success:enable /failure:enable +Auditpol /set /category:"Account Logon" /success:enable /failure:enable +Auditpol /set /category:"Account Management" /success:enable /failure:enable +Auditpol /set /category:"DS Access" /success:enable /failure:enable +auditpol /set /category:"Privilege Use" /success:enable /failure:enable +auditpol /set /category:"Object Access" /success:enable /failure:enable +auditpol /set /category:"System" /success:enable /failure:enable + +Set-ExecutionPolicy RemoteSigned + + + + + +Start-MpScan -ScanType QuickScan + +reg add "HKLM\SYSTEM\CurrentControlSet\Conrtol\Terminal server" /v fDenyTSConnections /t REG_DWORD /d 1 /f +HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "DisableCAD" /t REG_DWORD /d 0 /f + +# Set SmartScreen to Block +New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "EnableSmartScreen" -Value 2 -PropertyType DWORD -Force + +# Force Group Policy Update +gpupdate /force + +Disable-localuser Guest +Disable-localuser Administrator \ No newline at end of file From f5e8ef2b2109366d7bd1b5bcf36254c8c0be1c5d Mon Sep 17 00:00:00 2001 From: NotMaxwell <142256213+NotMaxwell@users.noreply.github.com> Date: Wed, 25 Oct 2023 20:07:41 -0500 Subject: [PATCH 08/93] Update SCRIP_WIN_CP.ps1 --- SCRIP_WIN_CP.ps1 | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/SCRIP_WIN_CP.ps1 b/SCRIP_WIN_CP.ps1 index 1c591dc..0e62af9 100644 --- a/SCRIP_WIN_CP.ps1 +++ b/SCRIP_WIN_CP.ps1 @@ -36,20 +36,15 @@ auditpol /set /category:"System" /success:enable /failure:enable Set-ExecutionPolicy RemoteSigned - - - - -Start-MpScan -ScanType QuickScan +Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name DisableCAD -Value 0 reg add "HKLM\SYSTEM\CurrentControlSet\Conrtol\Terminal server" /v fDenyTSConnections /t REG_DWORD /d 1 /f -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "DisableCAD" /t REG_DWORD /d 0 /f -# Set SmartScreen to Block New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "EnableSmartScreen" -Value 2 -PropertyType DWORD -Force -# Force Group Policy Update gpupdate /force Disable-localuser Guest -Disable-localuser Administrator \ No newline at end of file +Disable-localuser Administrator + +Start-MpScan -ScanType QuickScan From 7478436688514a1036ac14c2c439b4159bfb96da Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Wed, 25 Oct 2023 20:23:37 -0500 Subject: [PATCH 09/93] gitpull --- SCRIP_WIN_CP.ps1 | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/SCRIP_WIN_CP.ps1 b/SCRIP_WIN_CP.ps1 index 1c591dc..0281027 100644 --- a/SCRIP_WIN_CP.ps1 +++ b/SCRIP_WIN_CP.ps1 @@ -36,20 +36,15 @@ auditpol /set /category:"System" /success:enable /failure:enable Set-ExecutionPolicy RemoteSigned - - - - -Start-MpScan -ScanType QuickScan +Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name DisableCAD -Value 0 reg add "HKLM\SYSTEM\CurrentControlSet\Conrtol\Terminal server" /v fDenyTSConnections /t REG_DWORD /d 1 /f -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "DisableCAD" /t REG_DWORD /d 0 /f -# Set SmartScreen to Block New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "EnableSmartScreen" -Value 2 -PropertyType DWORD -Force -# Force Group Policy Update gpupdate /force Disable-localuser Guest -Disable-localuser Administrator \ No newline at end of file +Disable-localuser Administrator + +Start-MpScan -ScanType QuickScan \ No newline at end of file From d332ceca25c844c415379a5291828b6557a2dbc1 Mon Sep 17 00:00:00 2001 From: NotMaxwell <142256213+NotMaxwell@users.noreply.github.com> Date: Thu, 26 Oct 2023 01:59:53 +0000 Subject: [PATCH 10/93] Add files via upload --- Scripts/Windows/SCRIP_WIN_CP.ps1 | 48 ++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 Scripts/Windows/SCRIP_WIN_CP.ps1 diff --git a/Scripts/Windows/SCRIP_WIN_CP.ps1 b/Scripts/Windows/SCRIP_WIN_CP.ps1 new file mode 100644 index 0000000..bd96d66 --- /dev/null +++ b/Scripts/Windows/SCRIP_WIN_CP.ps1 @@ -0,0 +1,48 @@ +net accounts /minpwlen:10 +net accounts /minpwage:10 +net accounts /maxpwage:90 +net accounts /lockoutduration:30 +net accounts /lockoutthreshold:10 +net accounts /uniquepw:24 +net accounts /passwordmustmeetcomplexityrequirements:Enabled +net accounts /enforcepasswordhistory:5 + +stop-service remoteregistry +stop-service SSDPSRV +stop-service TermService +stop-service UmRdpService +stop-service upnphost +stop-service FTPSVC + +Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True + +Set-Service -Name remoteregistry -Status stopped -StartupType disabled +Set-Service -Name SSDPSRV -Status stopped -StartupType disabled +Set-Service -Name TermService -Status stopped -StartupType disabled +Set-Service -Name UmRdpService -Status stopped -StartupType disabled +Set-Service -Name upnhost -Status stopped -StartupType disabled +Set-Service -Name FTPSVC -Status stopped -StartupType disabled + +Auditpol /get /category:* +Auditpol /set /category:"Detailed Tracking" /success:enable /failure:enable +Auditpol /set /category:"Logon/Logoff" /success:enable /failure:enable +Auditpol /set /category:"Policy Change" /success:enable /failure:enable +Auditpol /set /category:"Account Logon" /success:enable /failure:enable +Auditpol /set /category:"Account Management" /success:enable /failure:enable +Auditpol /set /category:"DS Access" /success:enable /failure:enable +auditpol /set /category:"Privilege Use" /success:enable /failure:enable +auditpol /set /category:"Object Access" /success:enable /failure:enable +auditpol /set /category:"System" /success:enable /failure:enable + +Set-ExecutionPolicy RemoteSigned + +Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name DisableCAD -Value 0 + +reg add "HKLM\SYSTEM\CurrentControlSet\Conrtol\Terminal server" /v fDenyTSConnections /t REG_DWORD /d 1 /f + +New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "EnableSmartScreen" -Value 2 -PropertyType DWORD -Force + +gpupdate /force + +Disable-localuser Guest +Disable-localuser Administrator \ No newline at end of file From 4d73e2dc3e80e2845eb57b4caeb8c35570d1115f Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 30 Oct 2023 12:37:28 -0500 Subject: [PATCH 11/93] e --- Scripts/Windows/SCRIP_WIN_CP.ps1 | 50 ++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 Scripts/Windows/SCRIP_WIN_CP.ps1 diff --git a/Scripts/Windows/SCRIP_WIN_CP.ps1 b/Scripts/Windows/SCRIP_WIN_CP.ps1 new file mode 100644 index 0000000..32845d7 --- /dev/null +++ b/Scripts/Windows/SCRIP_WIN_CP.ps1 @@ -0,0 +1,50 @@ +net accounts /minpwlen:10 +net accounts /minpwage:10 +net accounts /maxpwage:90 +net accounts /lockoutduration:30 +net accounts /lockoutthreshold:10 +net accounts /uniquepw:24 +net accounts /passwordmustmeetcomplexityrequirements:Enabled +net accounts /enforcepasswordhistory:5 + +stop-service remoteregistry +stop-service SSDPSRV +stop-service TermService +stop-service UmRdpService +stop-service upnphost +stop-service FTPSVC + +Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True + +Set-Service -Name remoteregistry -Status stopped -StartupType disabled +Set-Service -Name SSDPSRV -Status stopped -StartupType disabled +Set-Service -Name TermService -Status stopped -StartupType disabled +Set-Service -Name UmRdpService -Status stopped -StartupType disabled +Set-Service -Name upnhost -Status stopped -StartupType disabled +Set-Service -Name FTPSVC -Status stopped -StartupType disabled + +Auditpol /get /category:* +Auditpol /set /category:"Detailed Tracking" /success:enable /failure:enable +Auditpol /set /category:"Logon/Logoff" /success:enable /failure:enable +Auditpol /set /category:"Policy Change" /success:enable /failure:enable +Auditpol /set /category:"Account Logon" /success:enable /failure:enable +Auditpol /set /category:"Account Management" /success:enable /failure:enable +Auditpol /set /category:"DS Access" /success:enable /failure:enable +auditpol /set /category:"Privilege Use" /success:enable /failure:enable +auditpol /set /category:"Object Access" /success:enable /failure:enable +auditpol /set /category:"System" /success:enable /failure:enable + +Set-ExecutionPolicy RemoteSigned + +Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name DisableCAD -Value 0 + +reg add "HKLM\SYSTEM\CurrentControlSet\Conrtol\Terminal server" /v fDenyTSConnections /t REG_DWORD /d 1 /f + +New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "EnableSmartScreen" -Value 2 -PropertyType DWORD -Force + +gpupdate /force + +Disable-localuser Guest +Disable-localuser Administrator + +start-mpscan -scantype quickscan \ No newline at end of file From 3f2ac8254d616169e84bac14fd165ff756d4a003 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 30 Oct 2023 12:37:55 -0500 Subject: [PATCH 12/93] er --- SCRIP_WIN_CP.ps1 | 48 ------------------------------------------------ 1 file changed, 48 deletions(-) delete mode 100644 SCRIP_WIN_CP.ps1 diff --git a/SCRIP_WIN_CP.ps1 b/SCRIP_WIN_CP.ps1 deleted file mode 100644 index bd96d66..0000000 --- a/SCRIP_WIN_CP.ps1 +++ /dev/null @@ -1,48 +0,0 @@ -net accounts /minpwlen:10 -net accounts /minpwage:10 -net accounts /maxpwage:90 -net accounts /lockoutduration:30 -net accounts /lockoutthreshold:10 -net accounts /uniquepw:24 -net accounts /passwordmustmeetcomplexityrequirements:Enabled -net accounts /enforcepasswordhistory:5 - -stop-service remoteregistry -stop-service SSDPSRV -stop-service TermService -stop-service UmRdpService -stop-service upnphost -stop-service FTPSVC - -Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True - -Set-Service -Name remoteregistry -Status stopped -StartupType disabled -Set-Service -Name SSDPSRV -Status stopped -StartupType disabled -Set-Service -Name TermService -Status stopped -StartupType disabled -Set-Service -Name UmRdpService -Status stopped -StartupType disabled -Set-Service -Name upnhost -Status stopped -StartupType disabled -Set-Service -Name FTPSVC -Status stopped -StartupType disabled - -Auditpol /get /category:* -Auditpol /set /category:"Detailed Tracking" /success:enable /failure:enable -Auditpol /set /category:"Logon/Logoff" /success:enable /failure:enable -Auditpol /set /category:"Policy Change" /success:enable /failure:enable -Auditpol /set /category:"Account Logon" /success:enable /failure:enable -Auditpol /set /category:"Account Management" /success:enable /failure:enable -Auditpol /set /category:"DS Access" /success:enable /failure:enable -auditpol /set /category:"Privilege Use" /success:enable /failure:enable -auditpol /set /category:"Object Access" /success:enable /failure:enable -auditpol /set /category:"System" /success:enable /failure:enable - -Set-ExecutionPolicy RemoteSigned - -Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name DisableCAD -Value 0 - -reg add "HKLM\SYSTEM\CurrentControlSet\Conrtol\Terminal server" /v fDenyTSConnections /t REG_DWORD /d 1 /f - -New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "EnableSmartScreen" -Value 2 -PropertyType DWORD -Force - -gpupdate /force - -Disable-localuser Guest -Disable-localuser Administrator \ No newline at end of file From 7831a9b55d2e218e1470fd8ddb785f58e0057d4d Mon Sep 17 00:00:00 2001 From: SavageCabbage39 Date: Tue, 31 Oct 2023 10:28:36 -0500 Subject: [PATCH 13/93] Yes --- Scripts/Windows/SCRIP_WIN_CP.ps1 | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Scripts/Windows/SCRIP_WIN_CP.ps1 b/Scripts/Windows/SCRIP_WIN_CP.ps1 index bd96d66..d308cef 100644 --- a/Scripts/Windows/SCRIP_WIN_CP.ps1 +++ b/Scripts/Windows/SCRIP_WIN_CP.ps1 @@ -34,6 +34,10 @@ auditpol /set /category:"Privilege Use" /success:enable /failure:enable auditpol /set /category:"Object Access" /success:enable /failure:enable auditpol /set /category:"System" /success:enable /failure:enable +Set-ExecutionPolicy Bypass -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1')) + +choco install malwarebytes -y + Set-ExecutionPolicy RemoteSigned Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name DisableCAD -Value 0 From 394f9ada9afaba2b6a07d7c2f8a0f869f14b0b6b Mon Sep 17 00:00:00 2001 From: SavageCabbage39 Date: Thu, 2 Nov 2023 20:16:36 -0500 Subject: [PATCH 14/93] Polished up some stuff --- Linux CyberPatriot Checklist.txt | 46 ++++++++++++++++++++++++----- Windows CyberPatriot Checklist.txt | 40 +++++++++++++++++++++---- fwunixref.pdf | Bin 0 -> 69512 bytes ubunturef.pdf | Bin 0 -> 77789 bytes 4 files changed, 72 insertions(+), 14 deletions(-) create mode 100644 fwunixref.pdf create mode 100644 ubunturef.pdf diff --git a/Linux CyberPatriot Checklist.txt b/Linux CyberPatriot Checklist.txt index 306a899..cffcfc8 100644 --- a/Linux CyberPatriot Checklist.txt +++ b/Linux CyberPatriot Checklist.txt @@ -1,6 +1,7 @@ PRIORITY * Open README * Solve Forensics +* Secure root (terminal > "sudo gedit /etc/ssh/sshd_config" > set PermitRootLogin to "no") * enable/disable ssh (depending on read me)(install openssh-service to enable/ “systemctl stop ssh” then “systemctl disable ssh” to disable) * Check for daily updates in Software and Updates (Ubuntu specific) * Remove/Change user accounts/admin privileges @@ -13,7 +14,6 @@ - Security tools to install (“sudo apt install [PROGRAM NAME]”) * Clamav (open it with “clamscan” after install)(virus removal tool) * Gufw(firewall) @@ -22,7 +22,8 @@ Security tools to install (“sudo apt install [PROGRAM NAME]”) * Bum (Boot Up Manager) (Use “sudo bum” to run) -Looking for media files +Looking for media files and hacking tools +* Before manually checking for files, cd into the "/home" directory and run "sudo ls -Ra *" * Use “ls -la” to also view hidden files * To search for files use “locate *[filetype]” * .mp3 @@ -34,20 +35,21 @@ Looking for media files * .bmp * .gif * .jpeg + * .pdf + * A TEXT FILE CONTAINING ALL THE USER PASSWORDS * “rm [PathToFile]” For solving forensics +* If you need to find a user ID in terminal > "id -u " * Custom script wip - - For password requirements Pam.d 1. MAKE SURE libpam-cracklib IS INSTALLED!!!! 2. Through terminal (“cd etc/pam.d/”) -3. “Sudo nano common-password” +3. “Sudo gedit common-password” 4. Find the line that says “pam_unix.so” and add “remember=5” 5. Find the line that says “pam_cracklib.so” and add “ucredit=-1 lcredit=-1 dcredit=-1 ocredit=-1” (Enforces password complexity) @@ -57,14 +59,42 @@ For password requirements Login.defs -1. Go to terminal (“gedit /etc/login.defs”) +1. Go to terminal (“sudo gedit /etc/login.defs”) 2. Set “PASS_MAX_DAYS” to “90” 3. Set “PASS_MIN_DAYS” to “10” 4. Set “PASS_WARN_AGE” to “7” +ports stuff + 1. Use "sudo ss -ln" to display all ports + 2. Look into any port that doesn't have "127.0.0.1" if the readme doesn't specify it (still make sure you know what you're doing) + 3. To close a port use "sudo lsof -i :$port" + + +Networking stuff (more advanced. Don't worry about these until later rounds.) + * Enable syn cookie protection ("systemctl -n net.ipv4.tcp_syncookies") + * Disable IPv6 (Potentially harmful! Only under certain conditions.) ("echo "net.ipv6.conf.all.disable_ipv6 = 1" | sudo tee -a /etc/sysctl.conf") + * Disable IP Forwarding ("echo 0 | sudo tee /proc/sys/net/ipv4/ip_forward") + * Prevent IP Spoofing ("echo "nospoof on" | sudo tee -a /etc/host.conf") + +SUS Users(AMONGUSAMONGUSAMONGUSAMONGUSAMONGUSAMONGUS) + In terminal run ("cat /etc/passwd") and look for people that are: + * uid 0 + * can login + * Are allowed in the readme (CPDiscord told me about this one) + + Find fake admins/roots + * go to "/etc/sudoers.d" and make sure only authorized people can sudo + * go to "/etc/group" and remove any non-admins from sudo and admin groups + Disable guest accounts -1. Go to terminal (“sudo nano /etc/lightdm/lightdm.conf”)(might be “users.conf”) -2. Add the line “allow-guest=false” at the bottom of the file \ No newline at end of file +1. Go to terminal (“sudo gedit /etc/lightdm/lightdm.conf”)(might be “users.conf”) +2. Add the line “allow-guest=false” at the bottom of the file + + +Tools and extras: +* http://whois.domaintools.com/ +* https://wiki.ubuntu.com/Security/features +* Check service configuration files for required services. Sometimes can get a point for finding a wrong setting in a config file for sql, apache, etc. \ No newline at end of file diff --git a/Windows CyberPatriot Checklist.txt b/Windows CyberPatriot Checklist.txt index cba2ea6..55b09a8 100644 --- a/Windows CyberPatriot Checklist.txt +++ b/Windows CyberPatriot Checklist.txt @@ -18,12 +18,14 @@ Competition Checklist: * Change admin privileges for users that need it, and those who do not in User Account Control (type UAC in windows search bar) * Delete and shut down Autoruns in Task Manager. (Go to task manager, either ctrl+alt+delete > task manager or win+r > “taskmgr” then the startup tab in which you can disable or enable apps). * Disable guest accounts (command line > net user guest /active yes) +* Disable admin account (NOT THE ONE YOU'RE LOGGED INTO. THE USER NAMED "ADMIN".) * Change Audits to log with both successes and failures in Administrative Tools. (Search > Administrative Tools > Computer Management * Delete music and games in File Explorer. (shortcut is win+r > “.”) * Delete non-work related software from the device in Programs and Components. (shortcut is win+r > appwiz.cpl.) * Disable Cookies within the browser in Firefox. * Enable the ctrl+alt+del secure logon * Use SmartScreen online services(Security and Maintenance)=ON +*Enable Automatic Updates * Stop and Disable Services in the services menu (win+r > services.msc) * RDP * ICS (windows-r, gpedit.msc, computer config, administrative templates, network, network connections, prohibit use of internet connection sharing on you DNS domain network, enable) @@ -43,8 +45,7 @@ Competition Checklist: * LDAP * FTP * Enable security features in Windows Security. (Settings > Update and Security > Windows Security > Protection Areas, enable as many as possible) -* Run a quick scan on the machine with either Malware Removal Tool or Windows Security. (either win+r > mrt > Quick Scan or Settings > Update and Security > Windows Security > Quick Scan) -* Update Firefox through Firefox. (three lines > help? > about > Update Firefox) +* Run a quick scan on the machine with either Malware Removal Tool (Malwarebytes) or Windows Security. (either win+r > mrt > Quick Scan or Settings > Update and Security > Windows Security > Quick Scan) * Password security (win+r > gpedit.msc > Account Policy > Password Policy) OR (win+r > gpedit.msc > Account Policy > Account Lockout Policy) Enforce password history: 24 @@ -67,15 +68,42 @@ Competition Checklist: * Update the computer last, just in case, Taskbar > Update or Settings. +For updating browsers + * Update Firefox through Firefox. (three lines > help? > about > Update Firefox) + * Chrome (three dots > Help > About Google Chrome > Update) OR (In searchbar: "chrome://settings/help") + * Microsoft Edge (three dots > Help > About Microsoft Edge > Update) (It's the same for all other chromium browsers) +For group policy security settings + *Don't display last user name on login screen + *Require Ctrl+Alt+Del before signing in + *Ty got too lazy to add the rest :/ +Registry Editor hives explained (if you ever need to use it) +* HKEY_CURRENT_USER (HKCU) - + This Hive contains the preferences and configuration for the particular user who is currently logged in. + If a different user is logged onto the same machine, then the information in this Hive would change corresponding to that particular user's configuration. +* HKEY_LOCAL_MACHINE (HKLM) - + This Hive contains the configuration for the actual computer. + The information in this Hive remains the same regardless of the user currently logged on. +* HKEY_CLASSES_ROOT (HKCR) - + This Hive contains the information which pertains to the core user interface such as file associations and shortcuts. +* HKEY_USERS (HKU) - + This Hive contains the user information for all the users that have ever logged onto this computer. +* HKEY_CURRENT_CONFIG (HKCC) - + This Hive contains the information about current hardware configuration. This Hive is linked to the HKLM Hive. +* HKEY_DYN_DATA (HKDD) - + This Hive is found only on Windows 95/98/ME. It contains information about hardware Plug and Play. + This Hive is linked to the HKLM Hive. - - - +Removing Malware (You will probably only need step 1) +1. Install antivirus (Malwarebytes is what CyberPatriot recommends) +2. If for SOME reason you still think malware is on the computer, look into the following: + *Process Explorer(Gives detailed information about running processes(includes virus count))(https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer) + *Process Monitor(Gives detailed info about file system, registry, and thread activity)(https://learn.microsoft.com/en-us/sysinternals/downloads/procmon) + *TCPView(lists all programs on the computer that are connected to a remote computer)(https://learn.microsoft.com/en-us/sysinternals/downloads/tcpview) Notes: -Look into Malwarebytes (alternative to mrt) \ No newline at end of file +idk lol \ No newline at end of file diff --git a/fwunixref.pdf b/fwunixref.pdf new file mode 100644 index 0000000000000000000000000000000000000000..dcb37cebd46737d330d032f9f3db4fb2befdae08 GIT binary patch literal 69512 zcmb5VW3X^Lqpi7Y+s3N}FHzw>z5iLdE9L6y1UhrTCvH6CR8?I71Jdw9*Nujm@K z(asnC^r!X}!N(p|dMfxeUe8jlE=-{ket364R)zT1Q1s>r%rb_K6142^4T)f%) zL*j0b_?ys~2er)(Uj(AMzYg#bseqKTyQc6u}$~R3-Y|RHUs8HOHo&&6)jV zHN5~CD5djd`Ob`d?4gs$RQ`_dKEB<9Li5=LmXWvd6N}tUxV-&b(0*TwuXc7nAlGbV z3fVrNd0Th9JU!1hTY9#9kO+!@3PKQH_-yxn?q=pl?{o6L$`siPE|lo556iOFN5a}a z^T2sFLi8AUlMXNP`i99NJWtn~g??Nyg!d_(C1c0ha#-|imE-< z-gCb}`34Mrlv4J#?0&zWw(frJn|gVEU7?kvZ!fVZM$Ns0Oe53*CDZ{yk=!(f$huKp z>kfw(rz&aa^%a4>=JI@hQ_s|%w=Gb3_`C#&%qhOEe(iqWMa2ksj_VeMKC}q;El9o- zz(>Wddt7I~bTbh1E?jZKYBcO3Mak58zp&kYM~C=e z#{!Q%ygyLtII49Q>~YnP3hA+~;TJ~1@%7=@MGoTOPz2!y@!5te|1L3=GbLkBUb6!o z7LZ&dP&5e?r%~ns5!6rqsy`H$QAR}pL{KjIeyH93jBr5Kpj+DuLo4#fgkoyIGqJFi zxf>5*;1S9vF_1x=nE()U7HTgWwl4s$A>{4u)y&*r7G_vkn0HmPM?lc?Eh@l+Sc_NMn#ODHDHw#Fg8K3-$#jK zGhWmtNI;vXr7K@KgQHaQemh1f>4c(wc|g+;7lgS-VNe6BJtCT*N0tN&fQrdp5enh; zH<=AUpUXG$PzA%GOsHj4OS?u)OxC|_PW`#a$;%*E!fUWTmEtBEU|I*DsH+mENXj|Q z)>#9NGcU+mE&@zAEPFt5fPW31VIxxa<`jnCP_zz-(k6ZxAT&hpXf%@-HY=8POSA(D zoUErKK8KQ%h)9Le`b#1wQP*Dy*i7Gz3%OwGHUYA)cG()QYOS7kR&45qR-t!-S+>P% zOu!!%Q?sNC&t+{;(-Ypl5y5gUV!*^o&9O?-PiPB1KaHBZv;1kUwsVTIX-!2HE~tl) zZ{0W~z)#7N6hdxh z!ec~s@4D2AF^1w(<|1O^#|Fj3Xk zXdRu21;(3#2>xsRDw_)Ib#^7%Vs->?r^d&VyHIvoXmhuFeu1TwlY+nBF# zAwMW%mti^~P|Q%uk=?5p=KZYQTDj6ZISH7A!Cf=IFVtHGF{&sNcrnO)th_axf%TcW za$;i;3=h*?jJY37L)L7V$dQ%X9Ps4QXL@qCG`y0?`b6n@kGrTjxlsN{Kyp!7D&GGE z6ZnHDlx?BCSitK#GlPj;za6G0{DARZZQ!0Z#^;&R+w+Jb6Rxyd^i>c^5?d`; zb(jD*mvJb5ZW-g06jth?1yr=9T*aquAIAeNN5ICJl2YWP9F>1q+f5C z`CYLz{ZvsWYHe5~>Xbg~p7}>$-)2s<_G{0JBt)&%sXYq9IdDZvUOst%^^IM;QjB;m z1@Y~I7&mrf2L}o8g-NqZ@o%bJ60FM$Vq^G-zUhM$nul5*Ko@)8tW2BJ^Tnr717yj?s*4V+bC)v*77uw zd;SzkLGcg2h7kx?7(F0(;}6igH|E%l4GI!`$$Qf`4cHL%1-0k!=-YLPT=1=y@!B%U zF8n8M5AXH*C@;`_WkPY^g6c$!z9+Lo-&COiZ4hfUgp`RvCrH=}mC`HjR1R>>rV{uw?GR28Y;~1}3pSOXh9i z-O-`NTX1$e^(`$}$$=VNOl?`v+|{bJz9L?}M59RxImQxUKtnv2t53wbRB%hgVlm{! zkc-)}DhkguZ0{GeQkmxMY5mV2L!zkN|XG-Grc8i7Yxs4xmh(1 z0?oz?&}z)=wK9W}FJ?@2ia%3~CYI?5DohhO(qVxVlpWQUm%@ITJ&KCk56|tjVrHLQ zw`;|S&m`ItzuLivrF$+ikzS_gr)>SnixlJf9qWlS-2pGAg$tH7!8h#aTlcjgx(AqY zSj96YL;lEhX7$7Z8;jwEXx{sQM-k_$`Mrs|z};;+;^@2MkeH;nI&k*Movb>qr z$~KH#YwTj=LZ~Y@B`y}UI*tZS6exx!<80cK1ePFA(7Ltx0J5Vp)gxlsSHLw>3tXD# zpcH$Rm!OHld64y+G>TnPYnQt8OKgQuk$R<}0C#daei^5m5U`A+?r)M7y;1L*2y@`& z`2-v4bATGFENoI#>mxSU;}4;~$+pB|TTsrWoZyDv7U5pkhn;tv{HV;}CAF zC+7%MSmIoaxJ$1b@E{fi>3FKYmyE9!QI!mWHhX*JSXyb} zoXKQz1*RFHsswArBS6UYDgos(SijM+M|XgdUiqltk<8YKj;9c#D8M0i$RC~3)8+S@ zf?L6pB1pIuWZolf9C&n&5#>DH6b%_>)W>Mx$R^Vfn?{~)!rYMSG~U(jGpA;n1aE7RolVtqD(d7)A?p7-;k6tzzOkW#wyc!ps$7-2@CE*PS1<17z zgTP7SFW7Cgz3H25#;p)xW(8R5C=nO?WMvM*Zj2t}FX@a?Qe+LABY?*iYDRu^!vHrd z@BNRU(!o02G~_x~lQT_7F48cnr`e*SS^p=j5mwhUeLMUmJBLFI1ux=>8IB7lBrY0d zvk`XRo8=6Nc*fJHt|-SuQywCq=bln>S2FJ8?JEbTbtV4EdValdNCgCF_EV$xApfIK33s)q}NgbG} zObOxyF#S}l)H{(DrX*P9iv2)B7Nn52h(6BL949tVIY>OC{IwzDS0r`Cm=6*->ESCD z#)~qt1>GhENCcEd3=rdsm;rZ>6Ksb~u#z
{suo>#2gZh4D)H;vnJ$J0`IQH7+5 z)-#Ed;>#H4T09Sy5G0E!Y}^!x=A3PK7YzkY766-DNl@gbNjntVOT(ARP6{r*xYLX>U<#S4lTmUwUuL-Lhg5^(?=6wSg&;E zK=EK!+-lG;)Au+%gJ|6(Bq&6gSfC5?9bb}#WX?@mrzOhBB!{BJlHMdB&BQZ0A`*gI zt01wvbm(0hjYpP{T>7mW$wM+oTE&%GY5ZspDLg`$)~K}^s!tTQPv|s zq(?aAN_2(7aws3>JK`7jWINCYPZqEK?z=sv|G}JH;UQADOx+tx_i7Uu3rpCQD#!%y zXc}M0cCL^>#XR-JKh88&p`Qw75y}Yb=@EHXNcoLHCI@PeCjYvQ5a~^YPFWQ|H)+Zt zMLDpX@5?vc%g$m&47i+!4Ja@Tg|=zMLg$`ev68|>dKbFHMopO4lQ37Gxq*+;F#~j> zuk_conO2f$L9&^oh#<+=7bK`P2C~SM;w=sdJ*a{E zYA2i$o{^88+-rk=Pt^p*S7`Grru;cn6t5*%^=TS))Z@82z`P+Y8nhx-7F%T!xxXYP5(cqzP>_xwTNCX=>sNNh}$&FNru* zIW3eEAUvVckG-M9y3M^cvAGQ8SrMqRtq4EQgxC*cm=2+`Z2~dr5E_DpNmt-}m%~s< zt*Z3)#=6AsMgWNbAF#vG+&-O{aTcG_M2pnV*%gKkPIp?0XGGNOOsbfc>1VT;mg+l7 zb}q3Wu_Ax7acKs+aE!W4B%v!ch6h&|Midfz!>V)wlXU02_Ck|^S#kZk3_7-%;qN%7 zUrQDMt$W%aKuPX0^XV)yHL^{*+Qy0(gG>|rVcUydr89z*wec38OkFjr#+*GTp|TWp#$6o`3eVokv6;M9oNcm-J>peR*1jP`Id83V zFpMk>E4JP8SFth`heNA;kshljDzE1WSyEGDImU<#phd?MS9*x-;&^S(Gx8%`d3d@6OkTJ!;S6vB&WIK|AvS9x;kW{v9OUsiN$N(dV){R;eZDNZ zQ(D34mUdjPk$g=$c&pVuL3}HjP@F$W+Vh(B<6s( z-T9xm?McgH-Hsnv*>cSnfCUQ=^m@wI9$0pRKGugWL#Es@@CbRLVZu)#fD0lln$p%Y#HB@^yR=Cg0c>`uv;UY!L3D z>gNy+@Sm@K$+Z*l^W^@K1l-xtWpK#uy=8aPh89ck%_+BYEu6TM3<{=4!M?6GnoY7- z^O86k??(1@Z?TC&D_#F)Ev3c+p*OBpsHBceuI(g(7H>tU2vHw zg*jK!eE%1z&OKw^CU-x&WV5f`xS}SJP+J=DqmagF(Yi!`6azYnC+@3W=7)+#$qSw- z&o)spX)Ha?VUQ@}2037vOrWi^;t=4QrfA(YW}A~PHFYq9op{MhOTDn+vwi6B&&e3A zZga{&&(#QP)U0}J)asYkX8uCk9O@=l9YW%;n9LQKKNB)pLVRV?`x<WrK($n+L$;U)@RNuJmF=U)|s>bYn)0k5Ju)6cqHwbDbqgjE5$mUgJ|V zyvHSFvx#z0p6q*tTr6ixj%n^MnyzZTI2+f>H+i`dwr(qyvuQ(zC1^+p8=`*-%yF3M zU~*Hu%!R#8-Ml_Spsbye=x7FJZi?;%%wJj+B4pnUmlsXxmNihmjm-WwHl!Fdw|De~ z?fi)_P&c-v2x%>nphiEzQUjX@ZD={QyW4VDi0T=E$rbVvyVbCU{sH4DiL+MR>2%6& zpLK(;HkK}r!}1N_Ck^^!WU~PLyJk4NZ{k>SY&J!0*}?|p-zKUg#fp|8^T03p2Nq)w zcFY|iwi*)7-{4kkB2$l>gJ~b#2b{_ho;&-Vu(U_BEk zER>0@@&C>t{%QRiT|oVtSp3^yWn|^}_wj!QS^hiNQ1-Alp;MPLv@|htrc-h;bpE$5 zVPjxsLZ@b7{7>Y;PESB5Zen3(?o7bILO>^I;p`-D;wWTiV{d0`V(U!6PVj$+BW(YM zBT)ZCIzlI8XKm-GWN%<(LMLqEYGGueC?*K?|IAEIQu|~F~Dk**9Rn!bHp#@)9DQ^ke5YpVMu6`ng0TQfcOA@Jtvl4d>^HhB;+DEI-|~(nKn9Y^jbi?w+L){5sg;yqPs&GFh?XSZ21~qm!_IL|cxvD554Y;?eQ@4+YJ{ zZ=Km7^?j*#)@sp4ML)QIrhS_>QP@Va$0o4%;w2@^bYtqoNS3_sxOZ2UA~^uAShgSl zuq-i;u&v(r%aPn-?NpbX$vq7YK@$tzO>s*f=uhhp&<47b-5oms%~`etBAd6`7(Lt@ zb=C%LzJ3!xgd?X+XnNw-dce=oxt|q84OOE$LGQ*gcDuc{-SZ3NQ*=;4?}r*3YhiU` zI3@ml`N0w;^zq$IIQQo!u48;=vTy)Jn!1Wwb-@Wchn5!aUQ+uG>J6MkKP3H2b9`HN z_xe@Y^)9j(hzRIEbBaz$E)l3lGj*x$Ome1{n>H~kRlsEozpLA~X3pFy$W{D_d8ens zlPOyUq`Sl{Hzx~s^qsY%nR~`y0DhXUTlahQtA^U(2(26G1DIB~@BBX?_V0K97b|8) z_WvS``TqxDj7%K=g%~UA|0`nb{~r+3BA}D7H8ycKG5&AZ{zaD?N|gCu5iqm#O%CJ9<)U()zVRSl?Viw!GtBDHC=o((= zs-?`{X8umo(5HNioRFVQ&*>>mQ%WQaPZ0Y&PeN|FFvUJ>meUW=Et)2Sh6nkNVfgAS zegB_srFWOT_K0NFejR=9NQ&mAUsEjz-E_CEPMU?~XPA1bAy@8#;*wgyID3o=NYV*h zf6UR_u8mU94?P3v=pUG?v0u>rBmR>8IzQ<48Qav0g76_yp&??U z-ETzms)*($p#O!y01nMF&u}?7LKXtniSRFFp1R3#&dNU_rTWsEuIjlyDrOq>=!TwFXc% z6-yUouv74QG)UY1q{fOq)ZghArQQguX!@1^)% z6rbK5{d8^E7mg8z2JOUF?!L@v{_JOxeu@nWH=3Q+6~#Na5Vovhv^qeB2Yw8)KeMhh zI}rzw-fXwOrKD z9?4qmBAU4m&M2xWgjCQ5gnqEub|+$tK(qp3iE;Y9S!^?w`xp6xr)(Ci1Yz1|{x#7B{_-nQSPH@fy^=dY}nZy-#Rjj2Et^{Fl!& zDxV{(f%^Tx)U1#fnJL=~5w!_-u-nmrre&42)`@ z1+}pY7+)$eyZ@B*|CHGygHukwIp154P{8l~_$=0-tS+BzY-TDj1kG+Wc0Sfl#jdMV z`a-E;MonfWg$kQgqTQhv9lVrq<@T?fWy-jS9*|zZUq)LWfoQYO zPD64b15A7Bu>yR70@L0kNgxDuI?=@0!_GJPu&=_&;*2TL8Q`%jB|!xvJ7Aos;ozJ~ zsE8o3TIsvKkJ?R!rt4}gC^2MnN(FE|2vx@7ER1E$OZW#Yuf+hW!!p?uNz1O4sA~`u z(bOx#&+VJ{VKMuv)wEjc7dYFxMNg&hmX=R~K6bzYsh=h*`bxyR8N1-EE~qgvVIbP5 zI>;QyBc&nTi_EYxO6AA+-*wRTge#oiDAWFZWw+Xnr{U_m?-6!h# z)yP8gK@^(oyK-G-OBZw_*Zm|UTq)&5okYLED=Y`9d_maCOb=+ZpEw5wkhTfByAGRw zX9D4VD_b(RDMDw;n;{oY{9sb^E1e$4?3bEl8*A{h?;ewJE(BD1c%sMl;SVmG1fZPk zq4#qp7%hbYx15gV_FW4*vDJhluX(=twUzAO78Sp?iZMjc2!K?andWL6_Y3V zg17MIcmA1euv)>o_JB6Aa`=qQuFU;5!d@T~Y^=QVbHFu3&+!raz_kYq6cmSWWo!+z z))Xz85k##<+TKCZW!#xw_8=|uVQKM%Bx)4tD&|k@zDeYrek@UjJvgm!{_N>fEd^@Alw(_H*nnED7oqd{u zJayz3LxX%f)36*0KGpph>|uhITc`G~i(og~e9wCaYF8>9P0W!n)8H4BU3ZiB0@|sE zKuZd*bU|a>3`oH))KoG1klNz$U;MnWXqD-CRusBHAs*r_P+awH0_}8!{m83X0__fR zjm!`+?dD~UQ{r~=FtVw9OB%Da7w1GC2UpDpU_RPHu39X}K_M_ItSl@_3Z29qyulhi zFCt$pi-)u%FF9o$4G}Qv+kOSXv#}#3J_1M@N=RBQgHXc=-`lScL z-A2{mbB`dsUYU}zD{i~0Y|O%R+lS86HC(*GTZ-A>+`*rCXeD5pH(vH38FvFQG7Dyk zV1mc}ng_XqH59am4V-|wACunvjb9vE;;Mh0#%}W1rKkw_0C}L+Owr&DOj>p6tLSiG z?FY&!3FmgAM0cj#krhyoyaTUBRa&d4GKZYKYpkUsXTT@K9!y`)Sh19N7gX?BZmgom zu4=kjEiP7{LL))kU3YX#uoe9tznihYA3PqrrP(k1+QLZ!{s%k!uSfmY4l}Yau>F@G zW}yFXL;Szbk})v+Yi9qa?b84C0s{d9D?2m&|FKQ-@^VL6^Eu~mGJUD>x%$r3Aw)1I z4L}%&2v8NLB79c&Am#Tru_(cnfKGJn=}L@d0JJt58+b!((;l-xzPv)HO}dgw(p`%= zT9(lEb1@3*9B}zcU?n7+m_ZNJ@pG+{GHCDnXKqrEm$Xv7-*&Fu4W_fN*}HE};_UDl ziSb}K;=t}Brh)To*I(7(d29%S&o^(u zYuKKfkTWwx%6S=yf%&;z_YS0j!@8l54~q15Io`sMv#9%SYfCbRSG5*5gJ4N#XCF>R zyzXl+fb$ghizn&(+w!EZ%%HQb1C4ChS@ATzA46DfzL5AUrUh~C25dem;^vG+^dbg| zkI}R|@XahcU_87K4jAgm7s1;K;cBiLDXsCr>a(r#Ty%u{v zK%G&acAz?cJHpih^ab2*$kV-GvrgI}J6uonoKP7Y?YkhNJb~AuvxT;Kif5D$R?Z;a z;S~B;AMJ>>d^$q7H3w|KJEn7uXSVz|Gl3%qJV?8uyCUfG#{1TL6i={QJLtQjE&!{F z`_@rNZQ*&;X5g&_)LtMT^zTsU1g`NseLTAn?hiP=$y#85U*cPf+s|`GH*hz9FD#vX zu?MGd3A&jm|Fg2_t}+D>hi=>+39N;-H@s&C&!~tVAO~YyPg(X_?fwS1Z*ljmtzbBL z-+-bqajs2}cv@%G&*;(UtLCuasd}zhe~^zGXsiHo98tUl&(NxCsGNsgUXq_1TD2In zg(CBnNHh80jO_2jsI|IR_=l0fS|-5>OvMVWAvIO)_Km|3EIGH|c=uBay{^a=woN!E zU?KWqIeOTq-WM#(IEr@=K2mOIg-Q_-UF2VsMeYz6LE^EZPPI85&7kTt+MKTDO#`P5 zN*&fUl(^baiH8-vN%H2?IKFTTRiId!HNOErm`tWZ$7l3i8&Tk}XS67dC>G8)hjorJ zSl=47_LKg$>TD_&jcGKepbC@?YOH1LN(nrA?sJACqSl2OG51Sv{wtmOQ z{A$-#U3u)`R3~l6ew2HUDG76aHcvLae(6!X60uW#UtAQCPI_6I`|U-)t{2PaZ*sj( zAV)r8ynf-A>(K~%n$YF1rtM|AG#Bc zF`hYVMEN(x$v>)+dWf`Fqebsqp$4{{3oI+N*||xXT?& zLCw7?hXbN!w2(AvBX_N+m~HH#0}sqeY*R(xwR7+lhEJ@Y#4gGOY4sX>RH) zFKw@Cl=Z3-eb1}!L#;;UYt4&Rn@12%=lpXa2_36qx(_e|R{B(|+eI}Bm?IfVR0x$& z47ky}n$W9^tayo|*)?m$5Gfn0m|XKPU$NJ)Y#{w{uqw@ZgVB^TpJNFy4Pm6pZ~deG z#^7@Z&KDz#A%;IbCUoaRloHP` z24hMQlX$ISp>tYYs%i2=v=LLt)WFx%;5e)af9g^GcmLPpzNU)f)XG!vKIm2M*ZqxI zj?6U#uf|fl<@rhPzE>Jzr$&*|R3}oIRJou%A<%38N-nu)1zt9c@CcG{H&3!Z>Z~z!4%= z@}A+a6WQ*w^=r+_0i4zozD~=_1?K7aFP`=K%bm-k%IMf%J%2ut{7ckA2RoiaW=$Eu zS-Rt9O&KA90--;`sd!dx7FkBno1>^Gry3x_k?h%KG$funcoaaf<6X>nd*RA1oXRFfGE|@)MLC)!F{870o7-bq z(ji&_vwJr>#)wYzlkH|0EFj7nH0%X>M~rC;A+d+Y)g;xPL@1GaY%`A%_p(-MZkbk{ zsZkl`r~{?`N=tF5$xgmI7HBKg(yUp9F_1(wZ{M+Vu|7ZBxH1|(*5L>nX|4)r#)o)=IdK)Pf$hY_vRy;s6Jc@RaG$!INhrPZ01 zyAlDnoTuneeC3=j*W0nA8}th{YDBY(*ZVya=I5<* z(ESFuOTFuE4PlCz3<~e^)!iN719WxcpL@)1YwM17N(I^)X)hlZ%s(AmzumVUA4HU` zI&cP(zIQGGj!-2t{q6Joiz)~^On7k$NLpHo&#$Y z_;h^P6v7(1XxM*GiyK#a#q;>u#h~@jiJa^UnFW13M>t;iju(shgWu83>f=Of(Rw}c z7nLAN$A|&7zPjRADw86KxxfyodK?sIV5cV=B(x2m9TjKY?=lnY)$oW5e|#^Q&+`oU z_KNB0@zd^hC(h>T0qtwJ@2lvm5$78n;SOY;XVTEVtgRT~Bs%la{IQiatMhMscNCOU z{Dc961wpBGe8#^8z61QMmp!9u9O9iV#|57H zmZ{gHoR>qmn49ntL3D~NqCB3(3>!5v*4#&2J=_>esA7m)?8n5bOoN|s_-^_eav8V# zmZ?iOfnMqGPIe&m_)4qYbxpk_&=G?(VN-YZ2JO!DCV{(d1$SK{Rz?5#L8#&A83pLc zwRw*Xi^gO&6QGwgV$RHr(*EcejRlM~y9A@9Gjq!|8A|o4?&Co$8q`opuvaW5D688r zbweAiEZlRD5>N%8Xkc=svm&}u-W6z?b$f9itRij5$>ssSl zSCc-MGsl(rslO}XjFh*WH_emb#<*vFQawDmHJ8B(b-g{JT*KPTmP%)(3f5$b zH>j+4!)v6x{U91<((?r?GOb=q$CiveC3C_tXwRUklX|&&AW7x+9WZ7;@-5%D3cs!5 z2w&^2#(Ve3O^*AX4aYa!<7HFdUQl0gk}&50{pFn~nxFmHHU_b+tDUWP>*jixY zj@<@*GuYLRb7`|_{75-wl8=MO+&HKJ2G@$$T>~d8wC}xd<1Oa%`ZVM=>x#SK>aP2< zBc^0Fws!kAdw(4uBNlcWVQ@7U);D68xK?wwuD+z6q4h3)9nyq~im}t$&{flFATrQs zw6J70RnXS^6Y!<;BSQ$sQUD6t1ItpS){1gsHBDCha7NrWv3jR*p_j8q_n~HY-L#+v{?Mbs!T)#ID7>FC6l>G}LJJ2Ce0FwxhbGL{*aBfR$Oc%@vS>u2}2 zn+Jb`+4J1?V`gi&@w!I*NO#PKk0rhTlh)@ZQ8mQk_ileT&vu86!HcTibUTgygITAe zr1sAVjk#W-C-7r@zXzUowkkEgJ_Fnz7+XIyHomVKwmoj0Q=Qan`~o^k;j^?${GQQ*F z*N79764DWo5Kc7#30qxTUkSW?*ZHL~4zV;V$_4D_QKTS&zUtu7wtgXg8GVa=+kJz2D|4^V- zfjeuf_GW9gjmkBfJ^W!+t?ZSmH{EBOSiZ~)yE`+piEnV?>~}{HMCG$t&?eA`AC)=G z`LygkKmZ4Xf2!;1btyjoxe1`f6ZFY>Y_}i&1@ipI)gzp51V6A_CFWK5xGZU>EL&YPnWraS zsuHOYigT2T=9HQfYFy8$mI)opV5wUK4Ly^YJ}nr3W?PQ8CPnHf?N+;}4+Qr99N*iU zh|ba3cT=f=YTCb4O?`=?mqq2lS;yquo=L7wq#eJG>aKV6eo}G4cI$fBq_Im;YGZuRR zPwf}d8{%rcVv;L`1yl_2vsH@m(UjWJH9)H+3bCxQI_zFnDY0z7*7Z!q{XA}-zw0@Y zujKxHli5=+>q(vEJ>Sa4Qi5A#<{E(Yrq-dlE2kM2e0nY%+D*JGw`0Ge;k_)8rNe~u zeBip2j?%Ihg;JFZ*p@$@vLFAPyd6_*q}J}3ceFfy(%V{wAnzYPvO75JQ-b&0*2s(y z8=LF%?(?ScK7I(A&PDKC5hHK){p&=WdKxF+5&PY6qQ$RBwoh#ZW+9$yCJhSpwkADY7n=dYO9+F*VrJ!d% z&&Qut_m|=rfa^^ack4=Yub))jk?(Z0Jr4n~cBnh4Pi-DTE4YkBBs0$(nX~G)xOZdT zAe}W81DQ-WCB!uwDh{V{P#rqxY@$eBXSyKs7WF{VBcE%I%Zn5Rk&2B5TD>S zGYPFOBG1zy3?(XzxXIAxCQ}qNeo&zv3o13nkcbi5nw&qqLYQb%Sq(k#{k>z;-I$h@ zRz}z`N%5vS`CMOL8KN>g8ECk&og~6&(b?F*q~?u6xRwQDF)Lspzg%CIVpHB}DsJHZ zGfP-om;;77GD4l6WCq0Ob9j8%kQz*=4Z@=0%?9u6figH81byQ zw593ZTQYf2XxL(P)bMaSh%3N3eSKwQUpTV~+`MQ-A#&v{t!x-Wm1J)#f zrr}gg%ajYv;D4+Py(u9CVumAwr7X-5paK7&v8 z%EQ3M041_-#UGLNq$M8O;|uHeoxuV{#Fu>}bQduKMm8?K4cVtw1d7vze-$8uN`lx` z$Xa9=g-PzYBoOrpk)TIJ+$hm@l3g7IoR{WZm|6l{JeSiklL#{Zta8)?qZ;xe$uf}b zWR*q88cU|_<2{MVN^cNdQX+G=`Qb1yHoy|NC_*H=&Qkvuv*Izj%<^K-40<(=NZ zC>nKi^R1|OT5ZmMondbu!*O+jd{E5532ab5wSa?kY__~Kfen9O`1}0&!Pz$fZS>Ui z!~n|QJbeg22rQpo@1UGrY;m9aO9j%O!-E1=UG?m&^0$OIo`c2#69Sfj()@*?n*c}ch`0~*H7+{+urz-S7~^7L)Z{XYRX!w)`(l% zURqs0z!ru7q*Kaj;yMeJ)y<)s-#ml^fA_Z1asu$Uf_mEo!5}%qXPz5ex4wUZdAHex zLHbK20t8wAWk4d}r}|nOWj8u}4QNN1%jcs{H#9L@^PeMb1?vR+1C0yFS1)w~$yFY` zC6Kr5?nBwPEb4qKdI#{QQwz0zXKfQ00{jm)TYsS2`z>BtA>`$jr9IU}LWv@&pJ)0S zr38R>yAv9aT85F(y;(T5sz)+R8XT==B9G-q$pvsXc4b1Muh0{c@c_FFDFQxXrZn21 z1KNc=m>H4fP84`q0LHbXfIu&d>`<$F!#3MDt4%v~MmI!29IbkaR_vldh3xwOwwM5!^HOn4HE2Lwo1X|*cz zcB5XE7Q`L&S_q-ojt+KC~2+AwQH_Hjl(T)j+OCdlpxrGte@%cU!+3)=T(! z-C;X4L5bWp`49Q^_JA`&*cn7p6&`Z~7>lWa^r4htm4rbTDmpTZ=7OtW3(SfyknP!@PS2OpBEREP(*oHm! zBP*O25S4cnd>rt)Y=eJ(+>%!0L1M^M`D&*eGROp&f=&7X845f&Nix(Rb0UX$fs{`( z@Gfl!r-MMAS{c=6>Q_l%vHdU7-U2AHWzY7;-QC@t!mV+4cXt|hcWoMXcXw-C8h3Z6 zad($~oOAD;duHamH}l0uM8)2jduLWfu`0-a@mniPwiS&n@i;S#HPEu?m{dbb0yfIrQ8oa) zyK7CvOTtF6tP&48XzVveh#uy)(L!O7(yNPG-VzfZ&tQ7)fT2%TW*WYFxULKoF{@+TjDASZ`mmMiNtV`*fD zwpU4~c40`46Al{pLfev^)u_yQq8v?3+ZECzz%XIg`WB?^6fbL6rKilLZ%Z_Y4#s zzQ~httjJdhh#Ds=UNU-S#EKnqR*Jm#v~2T*@aWzml{%uaN+m1t;&=3HJA7tky1B?R zj_MmK=9sqDZmL=Oq`u=5yr9v=D$ps@RU6r=Sf%hRlvB9=h6=SRKWbaPqVVI=EzNPsq^@1&X zh5f-Ns4!$n*Hq4c{-yN8t&j?l>Dg-=CG9PUiDlS&4(2JrJ)vuEgz2vM&4MSPCh7R+ z6qU8%SCvSW96st{fl$@e)UMJEs>Ac|O0;vsJ@N5mb*9?p)Rz)UMHa{I3Rd`-Q=-DKP`$Ll z=9bp(mT$7v9$oZ3Fy*i^rHm9M46-u)K_Fq77c^j3Gy41hhbX=3(0-Ehfo8t)B0H#v zaxu4u0InYI`U89|jsLzB523K}dc-|xeLtv;eR7f~LS=KZdOdB!xQ%w=jGqs?mAwH~ zq28V{C`%J8C0q5TL8)QZJbRqLwrn(smz(Sc(x#-i2K1 zJ-m=R0sKdL_3@~seW;*G_T#Vb)g&vKZN|(DMcr`qwgF0!jCm8<0wAS5-vNd9IvyDarAhGBu9^Q~7Kz!e_3)zqR?0Uced zN)uI+_aYov490lOQ-Mst&J0tDq_rERlI`=`e%HdEd;IdW$V?zyd0Szs>yCC%&m;B1 zh&g>9v;E4}=vDT+=1KITmg726=HrR{Mw~H@vL=?YI(CTg6pg?yf_G7ppo(%xK34o> zqz>tM9s1_V9KW~kb=Vw#PY{xeCIRwd3Ynlq=wgca5#K|kMV{iZvzL&oLz?pjipw#T z-`k?q-W`+cY#))HGN+6Z($vw8fy-XL#9n{`Qm^A9`H|ai>O*ZOTdux4X}wc{alJE! zZa%>yZG42xA*8=1HdW@LKEZ-K0xkA4X<#jb^lXCIkQSQopoHQ!xXcLPlA1G4nxN+^ zL=i6|B&$a39Q!?nE99CNfYAtJEQit(;hm)z{sy6={jlx>3_i~@dNba{N4m98$vxcz+V^(D$YM> z-8b+qEZooku2;&A?-;lx+jCY|;K$GYA4tdXBWh{Ru6t1UT!npOud83db7WRKm%d7B z1Fy`!#Mg>aRBamO-ILFHras!1qjmK4pYCfv#7$h)K9kp%#j}F`I6zu~I^sxip#r#6W)}eVPL`~I37h- z5|>)pFEI*M;P#GgG`$2HN-KhR`r?^ChXCCcBmyhHN}L}+_yIaiGP|Zcz(AG)T&eo1z$j;hC-pJb0!Nv5`1Ym7w z?nLxyIrwvwkdU3bHa!a`I}tq#7we~`fSrh$nTc7KQPSDa+R|9i*4*0k^AZybqo9-V zAEpAXPn7(V-u_2}9>Br|!zgTM|1TTD=TI0%WoJ_xwa=;k@eH4lOr`*$KPelfPh#d@ zMhE79*&qHA;l#r6H_XjnDI4ARDcc|>xWP+a(ddo5z(V>)6d^0iIL@;eu}2_QX5B*M zd;!Fc_g|?tvk194SyPjgJPw*UUkgf}CgAG>B3xFfAa}3qQI_E^Rz-A}iuM~tb{Jn5 z#p-Ho4jclz*f(Mi72htV21h2WT~zwuv-6)8sO?wRS56A7z1Mjw-vbH8`{PTgQUfO+ zJ#5dV*M#xP7n^Q|JkyuD_T=re=$Vj>eq}&I~ywgqhK(_aFx47P0PTWYh0DtCN2{zz) zDtdU2AKfr@Y~H@I; z+$SoIE~bC#Psq^8^v^5*8^KvRIynnl7&;PtDniEapXY#2;rwZ1anfdI0ucTGc)JL85;UR9rgd;YXEFt(R7KsRn$iJQ#niwfQl@1CdUDh>$j%?-pA~Y2y zu=8HAYGLtPxE6tuiik`=1(ZeItQs;p?Xosu^F4-_Hg4IHbSHc0j_={PwJR#ffcYyw zz~o@u!~1f{J2y@t3^8rSQzW*cZUVLA9hVjtNoWYEHzKNnwBF(5<9ERIB@)WI?9YQA z4Zw{^#11fLD+}wZ3wNZyOO$u;7xC}uzr?sL)VUZVNjdy{na4;?Eowa7dFOT~T$#ma zy?8H-u?u>H+OLJ6W^l!@2=av9Uc0c|3j}o?78e`VBeTKV_TG{>1o>c`~?JC=V%T@HaG?ok&d_ zIf`h;bQUM_CPH3Hz{TUVI29d;igSsx5*B5a$W(#bOpPHyUXq5t7dJLzR`99t9h4Sy zyay)itYnsO4mmq?PAQIfnGlh6=FxOLWP8$$EtxlN=Icxvf4 ztbO1xt23XG-UEr)tkVg2J6xM{qadEFFIXdN?`r9~J*KB76$$(iuZ~^biBK@A4d%LbWL!7=wI@=e!=?d$)v5nH=wOR5@ez$6~h*S#t^JFpS z1Rde#)QsDU5R5JSoaS7!hz`OSYTAXK}W8WVsjsA~A9d2=mcZDP^7DOEghFw7A@zjL;8MK1xpt zij{`5R?UY>3gr6`Nv$ofQHaj_gczZ=y7jc4Z?R7(8d1nmPAda_ZRR0;M+iZ|_hi_} zR;Q=boDL=^>Gs8kGE@DOHpMu~(;`>j$oxz7!uo?7i1VJ$d`7vC3vZ%tx^5;{v|H{; zi4_mGS)*MvT`qGwe+dT$)05O=Tl+M4!T`~Lo&XlHPNM{OJqxgc+F?1UGnQ*Kejj6G z343JB;RK~!qj^g7V3?o=2tkAg#GMr7HtNmx*duWdZF#Eb>p5OLqM)Y@6y~9*V>o`` zvJ3U3cz-Cohtk>X&RmLIll8&wD$&C~m?(FPBUAU){v<&gJ>pxo4RetuvSMFk!TZ;Xp2*%62-Rrdi?%b0%sJPn#aD3!PR# z8C{KykJssYr(2MNRiz(L0~AHc^HZRvC#1aGa2(PaFgCI@09phYG=;CqZp7PMPEACG ztJ^do=x&pCtKnpVxH2>A`toRw342RNs>GwtSO0vL(c1x9LEv+BX4n66zO)GWdanA$ zbtN9q2dSHa?LtL97wpS+rn+Hv>d@{@cUy#<;S{~fk*+w&1Xwp}Ol6oN!x)k=s5=}^ z%Ldsl2(NQFks&<#g;>J>MYk|LtirMPXl#G1!7N6Pig8?vxMtWYWv#(B)@~Rk`lI@7 zqY`o-vVkClaLQB6mtssamYKPMtS?D3MKNI|RWZjydGKYto#kS5J-LqDNnXsY*hVzd zmT{={p;D-}?MyL5S82jpYFh?nj}C;)aSjBX!stig-g zFNZ_LH9cAky3%#qIUJsmo50d5t1MvYl5kt;LVLY6NtjNmm1G6%VlM^)NmJk5hfQ)z;FV~4Ya=;-kBxi zv5%~G_{fe{Pl{poVXJr3ZmFQfJ2@c<3nuqFU0H0wQ#SxnANbaVNw`wKkNhxZ+K6&i z3~a)R(|PWwIUcyc%0|i(r2ai#qQuP1Y)?s9toTS|=n8tqVcf&$$*jGF3sc5Y27=AB z_*hX_t7;*yW<-xObY(UoTiJkpJ#}8xpF2hGh)D`M0k9Z zfNgb>6aeJ_G6@NpHJa(5@f7tn0|(RHY`4%nNj`D22lA_WC+>AkrA5YjN}u@)&K4S@ z`j<>j2gjWj?*wM^F=MaC{XK)VL~53A6mqp#fFJMfQ`KkewF+Q7j_{A~UB+8}{Y%#)%r)qag{d~@ufTDHR)E-m)# zZ6s#uA>#gZ%}2z@T@#K5tb^L0BWW%2K6M{#!wRz*0n|%!VXBU3Xgt8<2(BSI;mX_yK8CR_l;(s&6HB_J0+b5+}*Y7&wfe*@2iMF$x-dJ zGAd=EMR3teQKKl-5$GMk4nv>rpm>O_4~HyzokT1fb_r6(Js?xsY+FbvO1E&m zcDZ(5!`SBMM8CO)Wo7fGNy~(LjUlIovr;m0!zv_=LuvWd>(xd*)^Ew@yqjU{edK-H zW0S3RvIe(Ijnzktk@q{K7~xT!5gJ!PG@Kxe7O^M^qG1oZXOYo^{=2G!-NAz7PA+ZK zEs>!SDwcW;T{(|v+k<5bUjqn7sVJ%K+3^8lR$Vo}G&L@hf?jGm8hF}qBbZ1J%n12? z9wL#>%FLe!DLfD3VX^nAj>CS1*XcfEZOxBhi#nJH)ta}~eU3V_uha~Bn=J)X)!v0~ zdXv3<#Td4$a?WcU)~g-w+3;(EHI@duYej?sZcVL9Rq@0D)=j&ep;h5HGGafWh!>JA zTzKZex^mYJ^nT>7P1;6Wm>N8&B~O{-A7{AiNszd8k@A_F)tOA9JYTI?xT3sfl0yFg z^NLasw#vL0;!^~LMr|YYpnxN?TX8x|IPd)on%bYFO}{?^EnDimSP@hvGsw_5% zsq37`KZy%ayysijy$4iy5l(Fst+8lQ9k*m+!?f|Wi{DuJ0Q9D~62BP#06#hFn1{vH>>|<4EJ`x~ zGI#=RyzgLm=D~#di*@uk4bnhLwO{xC4?D*5<&S24YCGy0Kl$evp3DAXHjedRbXn9$ktEO)szk^Jvi? z;h7UEMuLA=>JdjB@J#eCX_G>kRSYCcAIC6~P1%lQ(M=Q~#_t+h34(&IrNz$+)}ckW zM#;~Bw?k=MN;Y7_hDQ-$z5>ZO?+>&+IWX(aUHfT6$h^i6_@04MYiu5}8LJreE>zDh z;NDk#Uis57NE$;&C~6y(q<5m%b0@4`OXL_Qh&prz&8n!#=YfE^PNIY3qVG7*H zGBuZr+`EKjp>1Io68f)WlXBbgu3@c2h0xI}Z-72s!l?5^puAgyeS>quh1yuvqE`s~ zEX0OS@@r)b6wip;VFv&#js0ZVhwD_V*BC{SL0DUZZKDTT9}UQG=RJuSC{PCXxsp_g9R`hW)a%|P>fs<;R^wKK z#{og4)f~p}F3k*qO;k^m^?Jbb5+tf_9bI{U zSDoj<22tP72WxcN#{BV^3axKcc~r9{TT8H*ug&AOpaUf8xed9>q3E=vzIs+AOD|;% z<;Dp@GVH#WOp#ymoc>Bna-v@}ec&5mt$woKJyw;yY#z6X)Qs%VzI&G~vtD@xGutkP zZs#$OuadbeveLaeRKh)aY^?5!Xz#)c#m^d!DucK{NY`vBH`ufm*)qOYhN*lBkyug1 zoK+c-+uUpk$lt8HcC81evw7LEJ+yh*xymwV>vNponRBe7L?Bs4g~3qciW9Z?cng`* z{3&10`5EPn*n9@qSj(Q46|eSmt<^ zqipiEfSfFn@kFyDv!fF1;tX@`u@D%5dM0HO?m=2g{J<}xK0v`*O-(S0!jF;!?$E<-6I4hgG88~9fF>yI6t!3^2vjLXK4Y5VSHhEs$c#d=|Hm6y65 z#a)Csx!Z&%%Z-H4l8Npf@nOYl(GAHRj=iN{8M9uY{Mf$@JhwW&zk1@B`PnB!n@{wO zA@T(c{k(MC=a5=r2}@+C>#B(fHy6#joTC>xQf}nj0{@VlannTrEe$#oMZ|VN!Ek|C zBm$Jt)3wt)C=*$G)7lqsGn9ZZAsap*u~i{ z*-<!W|fr1h%dqpRm#&zx6`1jWMYNA50pPa3+%PBjM~B2Q9E|+Lk#vRdWDy> z^>ZBu#k3RIfxJp?xP(%bN~-r~D|+z_yoB6Z3Ds901Vz-&jh+sGulJS5L33DsOWu8| zjbiWMP^8Q)1dHs%b4;dJeNR_eLq|G(Wl>x8RQpO9z{mr3wPk3PxA@zK%L>*Ox$7hlUrG97gb4Eyuj$_C-{NY;IAtpLfSyG% zNj8ZhW~Gk9KmYVXwsG9?PxD&}gwpgO>`n~w&qm--Vq4ImGmQo;;oD#E-NT$tOMI(>z*IvPW0DX8iaUycty0a7CJua zZmJ`{7POulRAVJScCfJ)E-rLys>6?v=#yo&= z?>sW3GnnTLZIYYR!8%7^@9$&qx;J=!WO&feyfz+=qF%;bI_s-6OZB>jt&5lsA!@H3 z&vzXK$}5V^<}Pca0$vTgLvxM+K}B6j*#r2F#*rnRE11cA#5renDM9$~RUcw2xE8lh zYXx2>yyrVy0cv*Z6}c_5&k4n4U#%^@*B6Tgc#x2Rv$aU#w!cH8b})6f zk@DjmL9xB0gXEd%`?fOzQtXV$n2TTbiDIB%y&Z#U*rvJI^}E0zZuV~$s|}QQG z8xfqw!GmHI5is&a3J|vi%cnm3-uRU7Xk`u82yV!;hGYqRL}aS(g;kg`AsWwz;qPH8 z&xvPo=LJM~4}rt8>V1wZA3QU+X9rFmWr*|)+{!SGb_{lH9#D`I;H$$RE@r_h4`lfw7=)j?fa?S;Rk;y*o7A5UMO6tQOyJd1`qiVa@yd*HL(~ z^?1xM(wLo0B&ZQX!XseU*8r8McfnF@2O#!gFnEug$Y|0NYv4ZaOCV)oW${vcq?ac_ zI{^g9n>~B+J}G_U;0dOWbdV|o>+gAk0_{svPf%02^YGie@Bs^7CIhTQGyQ!@Ef7Tn z;0;}pEy=MOfLvq|n%%XuEra9}aAJY=eqr~R=i;A{kTrt~brG*5lj;iUCqN?YSBSvt z*xWh?H1{~vbdOBIP0Zl{&jkSk-Me>YI;lF33-S@?Run9t=EKD;VLos)I|0&F^+SZm zh4`X?$j0SFj-e3;`vsH)dcY4X@p1fJDWt^VaAKD>SIJ*@$1?%0LSG(Y(4O?zp;!a~ zogy23knD%B*TPu=u^e>fkFSR8efYY$E8{i|t-}H=N$K6JPdy1(^9a+x2_q-|-8oEK zF349{E2waRULH7FKGuT!_(ToBQPf2PsBzl7hWZPW z-I=RGiQR+Lotl`*J@(Wv_NY z9IC0e?zf$^UQ~ShI=1(XyS4a-r-P`aW?81L4&>#E$Biobg~vkVI^e97zS@y7sp4>S zKvjAl99^}@!*L}(eYL)gTT7Q#ovyO1k}9b6TY3DbXc4;V{tX_dy6Sl{EiHyx3vg+B zI^lwVYT^R30qmHS^uf=s*O}i&VIF6Bxtn`+!I=VDv|2T)sjFSo6Y0w7s*}EAEG()l zB>{g|0@7AhWNXH#O{Av-r2tZpbeWi4{dVJV!OOW9I>LKWP0v8Dt)bISBoAS*(BoJ& z-n<8z1SHI$J&v$6L0es!c&O5Hy53|u0K1|`k#$pk5@PCXd!JuEYvd;ClEhmAr$L>q ztXVt@QJJWMp-wlRARUQ`k;3AdFR{#?l$FX!#iO97rmCi`lSa9;keH-W3p`wx|D&>h z!Y%Mj5G5&dJ^rM;t)3S1C)inJ{&0c%1nn-Be}K`GaxeAnnL2PgTy%Te;)eXFD!PlQ zhoggyDE{2=`l=OC%5j4yL$kjqk$iCnO_W|SDZ5*jOAmvqmT_%kWeW<>A~V1s5Mdd1 zQPowqfDy~^M-^8y4vq(wsP?-=fx6iLQJ9&$YNZEJqkUP4+q6O?NZxDN#uf##i9pA$-Rw0m`FH3`v6 zm@dUZ>g`;iqRFz->6%TMo~1Ex(+gt6nRj9N{&@iu{Fq zQHoWKb|j}kEg$qGa7vMO26jQ}rf5luwOZ|)+ZOOX%AOMxioRN_NRy-FhtNI>z5v5- z+qZgYidBNxZu=3D?)mr#EAoW5XK4!V7L(6cF(ML1m$o;h1WOBOp(_n|xFSIvIuj49?G4Cp` z;|g1Y=j}a^0%ha!mni5&nD~b%k2)&%d&L{-88@!$GSG1mkMCuFE-y1xE8QDc`ML z4MUzY5VOB;$mnz#CJ4SL}B2ay?>jpGMgD*IMR6A@laNs$J1#Re+tKUQ(B5C3{=s1KA)yuC0q722Y5100Gt zIUW^+k)))ee7FXxZ5;pTaQ^Jy26PhKDWk3*4S`kYsBs*~NB>qxxEPpu0ky=QAP}Bo z@bELYnt&|nr*}VHrLljAZa6N?l0rwt>TM5|p4H(RH~5CnN2Ff-Z|`S4p2jX?-p@DS zMlpDbiT3Mmy&kv|@N~~sL5PD|-%gW*1vCGZQ@Ykuy8LcMnz7|lV|K~0?n3f6*(T|0J<;Oci*-!G-l>EDQf6iCyfp4n)x?6JxV%OF^K%do8Fqr3?lgwZ|GK-Q{et5@q| zysE9dRvgsgC)kE2J)c>|kFA1P2%`8$J9Clg8l!|Gu98Z<(+%d!J!VsVag4DvDh=<% zdwf+-&9RIDhAe^?Yx(!BY`yBLcy}aNH>`HHV58ieXsQ%h>kwM* z^AQ&Dmb*^Zc%mLq@U>D&s|XBz9h~R24!BDtsE#W{7ED6%6s2{#2PHt}=FP7c{^#jGgG2{0S<)?y8#(2QIz(5Nv}RfACsvd=GLKtw>s}FQrhqsV?n}U;^^ALd zI6Ove`eGH6Aa?8DQEv2YPyw--V8OM36Jm_=&CTPRk|Y~~5yrs|cbhW|#4l{Rm^_QI zxx0K((cb$lzQIo;1^neq_poTE{NT)B8qG-yLhofUt=7@2K4X@7x z-hsVZtZQaNnrSC2NkKQ#ppTCNcvbl6gd*oAY?Uuzv8jl z;Y;mOPR^kS$JF$^y<>0Kixzhd(rvL>BE}mEb!%fRf;>xJ9UY}Y=nS{{CCCsitj3z2jzmdapB2`8875) zh)E8-3#Blh`zKhrI~7#qMpy2CMQ5TE##e`>johh1Gm~!B`}Pc@J$10@j{Y6H->NaZ zPswn;H|wV!3=7lyTj|3@Tdw_ zZq<hJ-|A+@{#!_lb!UAp^jUUgu=jB%pvAMJ)|;D zuEaq`sc3P%iapA0!5`{4sgIqaLcXO7=|~s!j{eS4&ZlOtC(Wu^!KB)*Zj%p?Ya`DT zFJ7Sq{+ec{JfPzW+G^n0_HB-ES7vYQH~Sw8J`ps9u*D6bx<~q(epB;g4$|*oD&33 zLNk~3sWPcx^IckNL{&qTF@hNZ z5N_zHaOt~LkB*wkg%3wqa-+MdjYIb_m)t%px@&&LzDW4fh&VbPJ}&P>+$Q`IAL*}x zckwTRptR3}oasiL(MOZgr@06VhIzkhyW+j|^dmlgcPZ(7TB8h~_#0|OAWfG2bo3(- zuA3gFrq%O>ACipleE59GJ>z_TF3qXuA2odT_?_OFejYy9YipeI&b)Rm;$M8K)lhz0 zZ;*e3a7_ulu=VEKAooN*9(6!@JG=lW+8Q6Kv*`P!M0}vSr5)umD4%IRo}K|_y4OtO zyMHjCzQgHKJky>66d8gBfLy+ms3o~FSNi#Ml5!VL{#NWH_0+qR_z1g?J_7d=uOpaN z-{Q&7$#ZjNZqc{7q{7i;%v7Abe43t`xsJG;^-jYldx5hvM+Lbk6_lKUk&*Jy6c#KVpxl9 zg>b>n-`laHAXSM0SNeemU%7OV8y7u821KXqi1<5-WczQ6u#6AlZ7?+_abAc*Ebh zXB_gTN^FjHv-O#$1@p`p;$0fsZ4x^N^PC$dMMzZ`7Eh4!bof|ycL;Lxh1~Ci-0#h| z{!TpP&7ARBn9&1KZ&P`gI^<1{_;+5c8~P1T$eSAR?@j4V53iQH=#&n=%#J2-S%&B4CC4JaQ}S-#KH_)ov<`<^iq0J(N}Ij@Q;OqY89k0T{h!hL_wh?W zA75Mdo)9Nyukmh9Xc3MV6!(%+P>a;@_Vz^_;gVyD5>oK?jv^t83Sd00L(pdo zUuDYgtbsiaVs$+!lJK}wiSX+af*{9de}Xyo$Yev9$kUp13uQaTQ=*P^)0pH4J0T{2CG!@?W)%#7zAO=9L|T(DAzzsh*AU*u z2^zk_SR1wa336L-L7Q`O?d{=YxO!}Y46l(G|7XG|B1D?KfLBB*M5?_HS=z!^#Q4{x z$c&5eB=#zz44q#-Fe^}tb&AA~2MO@@_QIj3c&(7po1_VZ=_4CVE{`BLpzd!1#9NSD z-u!9nrlf8M@t4$l2qE6;#LcvO>>=Lb#Lb)Wv>WBI+KwX=Fs+irTMR_M>jS){i8*LY zd|))iN8n*JD`MGTTDwxb8&aI93!Ux}%9M#K++w38(&uNSNi50MrG>tZaG;^U?MVjk z&TdMtdP;s})GUfkg1M$GESjNfLW?yEVMRyENs;;z;!b_t);|bA!?g2 zS=I>4j5j?IBj>9tnJQwG0Rvuc?)~JumE) zI=GL&X+&}5{huahc*F6@^&Ks%Ij@|0xmp_?SHUV)C6CT{o~(SSOPuIBhm z7wPN)NHZm7=`;xy`i5uHCR9uwR~Aw>JFla}IY5kF9N*jb3(YF7m~%Ms{?{Hz1M7+) zMSDL8OB$;~7^@^PD)2`?zDZ!(9%bCM2TS2~C)rdQ?fwMOZpR*g5xXLmSq|Wts*95) zC^kaI5%hf=82CGGnxNwu8LnpGnO=O7K)p`>8BtoIiAn4oGPRN?19n_2S(F4Z>4Wh2 zQ&*}PaTzsi;d~Prcx*8pQ6D;BTrM71+mX?sHS})$9NfKJ} z^Z!v6O~|L7Ga$6ddPWRH6b2KCGBT&4R>bq4| zubk;mmiPaOCky{qJo!&F`Cm*j>tB&%W+ry7Pw<$NlZcs%gY^?i=3xELQ1bs8N#^*R z_ivHpKfuoage3nfAMh_oG8@bPh$K(^fh7C?6G>L^Rf8sOYLvixD5&EDl9dT#6+$}- zXx6uO%V-2WVyVlD;WS*x#9^V^smM@)jXZ)Zz#pHRphm)ML7<4On-0>tK<->vULm?` zI_G9&VlU45Mgq0NGtkB3ckGUu&ABK4jV7LtB;*@`J3Qe}ShGja*MZFDs3vIGU?}6T8KM!XTsrPf; zb0L?^{~q5m-b=q_78mPad`LOV*&ja3F_s_spx$rry9povz-E3ueCm#WNBz~#pB-WH z8_$RAmGX#jg}=mSg`bC{!7qDuXGZG9!ylZRQsK zdvML48v8G~`OKeT-hYbluWI{$Ajr^TE!+`FZ3d z;$UIYrc-Q}S zh75_|st00i3JX^#f0|XZSkB*czlL$+!U;;>xaBiy#1yq zn=INu(1bf8k%ur zL>xO~Hr|YFbJkQj8o1(B*>8VqoU&s!G&B_fL!jR|P;-qA5W2#mg*{tflNAGs9NJj# zKMl=k^)~g;;PSN!tTCZ>*k?{sPKJQ!?W~3GIbigr%^RhNc_zATp*JhoII5~s#{~L} zhaA#+l|yW5TMIJO^Bi5mx-*}%9$X*^tG5d{G-UF{sbkBgXy_b)IW6hiA?`wn`gr)z z)uVAV!f8f_BFB<_SQTm?*{*xx9ly@>zF%$4dAnMlorPLUeLs|DtV0>JUGJ%1KverZ z`NOj7=Y)aZ(jy|FeyiQ=TS#~dw$pPe%j!7$E}{lmJK~QdG-2O;des6rm+vNy8nf5&jL6MwJPuR{i0%-?)8hUV|HC|h zR_h{WD|~2bG(tyrhW~@udu8#}{9Oc<@W||5u|}u+HoV!K=*+=0dXJ!^ajA(%<&twX zOV>cLnX!@ab+<|JY9mTZ1KAkU1Gz}^R`1y1bv)3u>c>V0B&-jlChi;wdiwf=P35|R ziF?k3G+zUgtZ?j_XWu8v4T znoZ3m!iyh^)>}Gtb@rf>f%MvRY%cIoD>)Bm1k_bjHc$(&a@q=gk2A+njjA1lU+EtL zvlc8gP7_M^UON{+C+092&}irX`Ioz!GAu@!gR zuqM0VyH)e^&saKojM&z`iWqqz4Oq;zsnU|Myxr0?(=yu4{a6`Y3~~$Av@omokk=nt zvwL){3oqhXUb3m@_Ikq)tMA^U9UcDpvqC(bpF8(FfO|eMuQLQ*9h zMw|YbU662pkFLG{#|3tJV;Jp$JSBsE)Z?TryE$V64u&lc>(gdj+vHKijOk$a?Ak@e zp~r`~+`+>jg+t~I2XavA3c|w!g?zP;+0(`(7C#pn)RT6VYB79OMv8}EyHm_gs@k9d>3-F2d7P*q|QF+sq;rHg9cEaXHe^MgWDe5 zf|6p<=Gvt`(eus84}+!eTsnz(X{~ohcWInFr)xFQ@bZjNlXU!^`zv)i2qa0ER3wu? zgmNjEBrOuJX0`gw=TEo+>mx8d_gozYbB!#c00?XXc8Co|@C1!OdF1 zX89`IPOFYwC_(y#MBjRLX!{lR#YTiTr4zHUe_S?UlW;v+%~mKgK^+b81af2K^e;s9XQJ z1M?80e5Q-afYlvdH}%az|Z$pW6=Bh%M(t-`=^xX+mW$b7aaj~@0{qd zBk0Y7T}SR-zZzrIEP(Y=E$GJ>JT`vH%psh*%lCUNkpNk=NuI?#3QXfs6D>y$_O{c3 zxdOh7LIEkoLSh#{Cs7F+b*>o-sv~zfMW&IFgxvT&E$WO6Z!X0wFdJKugspkOe0hc; zj=P<-urg@o^I{TZ;yj+WM6{sk7aAlCE}vJju*L&6JjKHCOp>w$C2o|g1d1K~Ue2U= zR7+E#^s(=j$ zihhd=jEWn~F}AhpKNo9Qsyzf=2Sdw6`vkUxYcbSd$-Z(kmnemzuma1b=f|S#=`>>n zvI{!RBk~5UzzwiPf-Qby7FABi>uu&gKm|zd;mG%hBietGZsP^_(wqy&BR>MLip|9i zHmO=xrj%v`I_rGy^`y$0fwdR=gBwDBH}<7bamJm>06V}1=iQ1N^8)78Tjdf5@P!S6^uAn0L^!N?4Mf5#0rq*Qpiu6pK?|01w)u zJbWj(>bojn4~#V{J?fjwoEAd;0kis8;h>tBN?z8|32T8zW=|zpcf20BA=gKD4L0rq ziCEJ`jHNfj(YmQgkrg&so!Ff_L>DPHk75SrNTrO)Wb(H9A^>H*A5->KPITnm@;AgA zWXo2<-rrOkf39Bs%8GkOy{#s;wF7y8DDvgDi>3=FR;>JFU3?$LV z4;aQd(O}t46d@_eSdF{9Szn;Kuz4lsWCx5lAHM9yq&A=|!wY=GCC$$w$)*hdouK|dnj8PSg8sH- zVE%W>z{bS%xzYy^v9Yle0sc6CwgI23|3BJ)_WfB2{Np<3XBqLY{(p{v`Qu)eKl=YU z?!Q+8f6D(qSr-3P)PJ%p0{**Y@pI>-|1r{@gZV#M7B{?Ly;T-kFSWeR`7UM5;z!7c z$yO3#1q>v51$u~v;m8EY7%5P}q*xQi$yj1NI9Z5Aq~mBnim-S~q7sdnm5L<1Vzu@a zuCX?h@@3myu54FEuN>U)tta)8ru5V2+v3#u=dVKPmO0pnX zJQasAHVGL>6Ks4QAnPrtEJmIYsDs+S>8aS8wE*Z=T-~4)4MBDQGY0 z{(64Y$^vyw5nMkB`KGruJ%*S-nez#b&=|(dy~Q}; z``OGrxBG)X9AOV$DCRqJkAi3pS1&A0lUT(Z?(Fwt3Ma8*^0D-+1Rhd5Ghe|x3tF0N zRV8jOIqa9;caV(z15apQ!Y7I3JfePyHG*%*ZU!fzo88x-__X@!kz{A?b;@ygr%QK&G zaK_>blPjQY0W<3klfD9RMpFk`7^`gn(eL5biQ*on9fqGJ5RS>a4B{dLen^k82-le{2KivNfWyVknvD39dn z^@*`FuW8@ur)myq&)^AUxH*3!^VBv4_I=DJr2^41%~c;p=_2s)*E2?%{6D;%V{~MF zfTug|pkiAc+qTV)la6h>?LFtz)@4d<2~?2g@uUk33=CRq(Vs zM5~)&tGCpl$n!2_9Vyh<)Cqa0$<`Oc*UK`#v{=JBde@);`gyV{AD#(v4O>KyO8@RZ z((S|tsslDlNPvhR5RnrszarU5#?MGaP-bNxUPXIpSQkGDb~0-X@X{qo|=N12IXkkWMa~y|Ik5OyI`~q z)d7NIERTwgD$|;-2No~996j;pwu5$~*|kteVn^r4NF-jD@0@3F*W2We&*zv&@n%eFp|rx?mgeDvFcn=)dhA|?$E-!FyYUq=)Zq4X*Jp^UW$xGu?mMC@I2cP^?3;R z#qswxA=gr~K-30fQm49QXdfJYKx*wgYi~XITv!8XYi`ef=R?`e=OQ-@Y2>QruJ>8x z3l@rRtd!X}5^Na>Tn;Iu0C6~2aNX9@eFRYknVY|6m4($i2QQ+29s$q^) z+TZt0oO}+4p@OCU+7H&HOG2x^5PrSl+qkIMSR`Tz3~3N<+e_Nh5Y`Z0%stD+wZti+ z&;Us}XaUFV`(Bd>%Fz_`4VAE@sttl3wQ}7t+S|ubco$!rrc>2<{c!^pdGWnq4dd;D z?Ghn>`3>Fl&S}Bc=cYV~d&u>&qw#rY3NBl#rl`sSxWHN1UGU)udPle8ny0ODkr4~~ zp$~{@01Ng}7HH2NFfq~un1z*DKvEoIN;>};MMjhmF+r*0tXPrESF%sO`q7+q7Bg6= zx2+_@=G*!A8SSwrmISO)Pg8@}7QYKx%MQIN%QCr&ruBI|3`JgzzR+u>2p@t@ureBXt8i$EO1r1HPP>E~|`q{?D#i=>Q@ z^o!PA(*QBh^d7qHJ|YRM@MEGL*6qbPyoT_2_eHA?s!4`A@!XImdztNx(-VBo&Q=Vs ziW~q^I8S_6uvBV|^$e<2?}L~=F}R~pskkz2QdFt^jDx@15~wtx(P&}e4u=`iIT%Py zghqbvn1YmP90dF^YayXrow=^3+JLqVxvRV52FBgZvAqpJkHl!NJuf}Elw58(b3r8L zESS4zCLP~#!8>|%!b^2(ZbL+hO(0GFhQq{?a{5|Q5D9_@vO;#smB+@{>PAxOP8LMc$y3bsrD~`U-^Gr_Y(s>?kc*$)@IF z)Bm)db2)jPhIg(m+N!}gSKg{#v32{-8;DR2Uk=5p$B5dH%XZtxBlC%rj=xrQ2K24A zy-duOxV%`S?i_25#yct-^c72Vow|s&5OpL7<4xNd-#zB6i&BmL-p>=*I<#rP{B>(Ov zXx&a$HbGlg`BvB*vu?JWn-}K-U$3Xr;}LRd@*2X+)4;gjWBMKS*av1;BsxPbU923W zURaQJ=C{TOQNna7%P)mQbS>3`lF@G;976HPs&@OcsP#5fqYbIGvffE9^wV*sV-~REm_Invf8Fzj zeu4n!6~>bQ2+_1SMZKK6zY(93M`cc48}e4n7QMsEdwC6U;UzKbiRfZC!ND%O++w+< zIDn+LmdAdG-LPktg2r;;GeQkqMnoXDUoSH8_O%P9{QqzY^%Dr4z14iVoJoH3Vi~MR z7K>IsY6lm=O<;wbsk7-VMw`msW4qzQJnb9K(&qARUJ)dYn zPC_2aZ4t8Mbnn+o)YMPOTy#nzUyNR5Jvq4Y z-_?i_oxTgFIH(K2N(5nBrO`U7S=`Js1huS}C+WOc*#59PpD&&P2Rsnf3&66^%O8S)#a)H3~ky4-cqv1+b z!>lU5w8{W0#cwcjwv9B?yARGQ=N#dhjJ0xU!x3ijXmFusO{`h?UQDiXShbVC@v^F zq*ry8Jg(nsiwpF2KzB;+X8&H#I9G*7e`M^@?`oNS!aI|Lww)-lQMs6ufof31bn#Os zyWH^t zoAac`0$QW;0c%%B9gx?!yPfMtl`CT%=svz z8|ED+!tcbT6&1;{6v1@k;=W*Sj=fv0&k;QB9<_M#<8o~-I`f%p9UdJ_;^u2eqt204 z*{&juA~Wqejio8mtaZ4j8NY%-xkgWFRjeqtLT5wDgyCy9Hk=0KQvtB1H+9k~(0FLOo5shg#N zQdks7P&pK5`l`eTp(9l?SFDBECRmh8FIe1r%tt;!f@MN)A z?k=<@LN7d#YHWCZj7)5b+Esh{<^pV<#cA30eMd8mvb>J1ehO*!?)jVlf%o#m@kl5= zHH7(!c6O?O+WXPl2MB{JbGPA5evT)w$(K~FA#W%_&iU(5pp7jCO?oRkd02E2PW>V{NWJ{9X z)h#-JVg9Hv@=f#j`OXZ!%yBX`)^d0$X_9PJz~|5p&g|QqWRBbCnJ^IHFgejb0#ZD9 zlqxCFFSOrb%NRSUJ^fKU-v6gO%0fY%EX%`~y_9^CjxovK+9q1p&DO7Ay7ULlyZ+dm zHSN~hxM}m0XU=Jm-uub(L$7;Fpcd!T_#6VB&kGh18aU-UoE|nedfu6RZfi5(60u|A zHD~hpJA?VbpP%0EwFX9&(=iB6B8@Zv;|WITX07k)7j*hH!Vx!GU~Qy%HW<8eBA zFHIWYF>WqS$^-AycFSn%jx8!AFotT1$ zovI{qc0RAOnb&lD4SMaE!GbNExq_|t*ULiwP~yeJ#PgK}PrC=JqSuLEL;W%Qvx?bs z5IO`>AyLuaH3MfOffT$GF_8HzhS)S%Ie0XZbC$9a^l&jykuSnzhG~Musz?QrM{^j* z)G~1SRxY>7$g+dZuyEdU(uCGT;3QcgfhhaK z>O1g0-YwOC>CytMW>)8Cdl>wC>#2@_~6diZ07PHB`1djck(4LF@V~ zWs9J{{*zQE_T$FXhK-Z8DC}Yt?FT_bE0KNFukZ|0c(87ZojM2k%}C-!3duF=(3HGY zhEDP|xDo}{Tjh=TRvKx@c5=09zFDgG@;hYGhnvL^%M+-RXx@(}#-}uPOLU)amp$)K zej4=!_2oLVjn|C8G|NVsF{y?i{^9IzpL8y1G3d4!^8?@BW6`-(0%i$j{)|FOnX1sZ zirDTc$G!5FVr3u7OI#>&Vg4=tZG!7%$-m7x(VQ0}nm^ynp!ZwlnTr$MW?ReTMC)}V zd+@Y1na?ZP)2Ktf#m=}w9lKpRD zFir9W{9XRVylu>uh;E1zPzSd+H&NVmSExMe(*YN9Ed_K3UKZ$okQ-8O4tyPC;hq*$ zOF~o9@p9SALuNtVjekDyt~~15$!}6m%ha^Qpx)?Y=&|RZ)U|4xH5}8nro);wS+w76 z1oL@eU|_hEJnVX}V+_B)y??zu(UnE-#9LcFUmmm>N?B`qr4PU#_f__|+$WhO2!tib zI_To}VeWo7;W5B&hr_&7ylWIVIB}qZ1TJ*win zXx7tEnXqXd4qLUCgW?n(Wi1x4TDR-GVDW|hMSvRO=a?pdTmRcx;=IB4p|x(C_B`+< zZv-X#I_|?2$NRem3N_Dp1#bC8EB*v)px8<+66=Tt3)def!IKuau|C7NslMM9{R8a- zbz0c{tMeS{FNgd~qn-Yn9PmqgeeQ&2x1DOne~B)1EueperJAqNv+8zo+p8MsMwNJe zvy1^@oR#^w{zl|1F)IJ=*muWIFR+9tkZv9wd6d641C5E$*MVb`3}#o(3(?$Z+ecdr z2IzhKI>GtLofCj1z`pl5lc~@g)!T(J^V12_fJe>{;yib?Umhvr{YOXDHib``ur|q~ zVO`R?eAW-OC#es*4>(^93JlOb#+__ch_cGE>@rg4{Fj0ki2Etla#mOKNi*HWn^mnw z=yT}vYNvE(df=uiOG@}?k168V8`*vVc0BnrLd@@DJ(P-Nj@%e%BHS^%OClf=@;^J7e&#BHDGp+*7*Qw>dNj<}$YB*5 zCt*KO7?QxC`WUK`t`fkyKq2pDOft3LqFjrNUjkPCw%M7s9-jb_Hk{P7 zonH4omR-85wbk~vPBx~gT_8JlY<#uv2Hy-AXv93ZJ^VBC=#g(A`$u?bH|?~oLIX*t zNqD<}j=Mv0HdjNty%Oq93H0j3wmGLx?mnZbRT7x{QokGgM2OoO^7^1|*F4AeVmH-` zyQz^+ACg1f!xpS?65}kma&tMzFCN43KC&eAG+Li1ov4<8WC#I)x{5_Seg!rk0AHuJ zZahbO>?6WZ3Ni!TZ2tX7YZMZlxzb~&i4S!OOjCxwi{Jc*P`Vq8wj4W;D}U+CP>&fE zFn`sBhlL&k9>W#C;lqn?A?MgJtOK;U1kKu*k*=siJ-N9_aw)8eagafB;0d4m?Z35z z3M#2U4tV9U<3~F|cJ?43o}B@n`=M?9N9WMaKq8J5{+#_@Mg~gVfgFk&%fzMdV~0O^ zaKA@H(0~5}!R>+KL)M=F=2D|%DqkHfHH#qwPTUENNQSC{IrGklB}KS~6Y{Qt*N%C^ zT$$><2jU5XzB6c%RBzYO96C8#3$ZeCGpC%`7sQ>HO z6w3Q6uwNT~y%|;cF$ta-%Xk5jTma)N*4IV2K+>gBeA^S(Oj5To#S+sQ3eB(sz9RuT zj+ks(s+t#%Pgosx{Tn0UKw3fP0!g=w=}1)u3Mul?j&xMfI{U^Y;O12gCWb)`>O1A3+)+KKa9F`Ac*yR=exhZ0g1r< z=MG?7Y?LqduBp7nHR9Afhi_0pE-D*{A^roUpH_pZ*MIvL^qrNwldf@ zxL~ubw59+n^(|Lbb|QV<*>ch2%x)Mg-eqRbWnrGJW&QL_rH@Qug|?3NfbhpOq9yxu zKdq(C{r&DJmwfn;&Z$L?CncBV*LE?5SY;$DoxF~6eoGy?ihX58b)qqt>d%Gt6YMjC z$nxICq9)@w=#8QhW@sqhnxdxK#q+Y}aN3E+@{{9lb`_3GRW~)6zj+B2rv`Ku=9iV) zyU@sf>BT`{8d=jCg21$FZ&8t9DR(2y7dr9C+DrvfG%qyHuZkwOR|Wm4S=|8NRr2hE zE;FRwmW*5~8J4ydIpRCPs|nBgiCR(Wya3jVPBke0;P1L{aeOC^GT)rIois-xUFh)9 zz+9ae|E=XJjRCxhXDE1k3Q?otDd1yd)C~gU|F0B4M z2)9U!9k@O({3YfM2|WxE_xNHi!x?=@EbM)cbl{jw+|LZ&=bbeK)29An1eX&9KtvO0 z5TFFZ#i>u1UIA#r{ngojAy$CyH${DL`nExMhO*-Y{^YT;>cmAG0aG~rt-bF`7y1&P z<5u!@pj-b4vPc=1G>m~0FJ}d`C8tnHB1=9i>yy!|ZMiK%O{h0%H~HInavqG^bHe+Y zzAxulc#kU_;&pvJW3UeA^i_ZA0_A+1I+^v0BF-$U1p$A3JwZWu4&Smg?TelvxrP0P zGv^qlhkgRpt+=-m)bRT`{pfpl|5SDKL&2mVglKG~XKJJ{+=4X&2FRFC9F0o7i5UGr ziL6Jy40q4s+aKMH21-)sWqYAEM(9cNNjzL#f)Cc7x@| zIfXyu^M>)5kk1VH3;| z_Ig!<{Y0^19ogICTuxL!0UzCF6Akd0l2;pW2Pb(b$Ac%;x^GS8J8TpJ>Vr;4L9o&hS# zx%(Le8V5__6ddMBg7c+8n;l3{%phjhv13ukhZY|Go_8dkTPasBGbFYp_m&kCp4{KW zS!V9Dh$va+8|Wgx9V)IB1!ak@YdcV7q0083kDOGJc_H6Ns6B?QQQR24JS|G+pM%k#w0TF4lEZzuB;aHo1dt$sv@@f+|={4rp}W4c!%QTTX%w9=$4MleLr_11NGI{|5MQ^_0`v}#rqks zBsd=J!jRD~B_h7_LyeJstl}dKrSu`$xXXS3T)hZm#Z^0YW{T%z?_G59!hY+|Y z8L11u%mBurl0kT$Sz-93MHwkljH5grI9@K)=<%m{>)G;`{2#VP z712v&!eOz2N*L{AF`D5PSlMLr-{lkJQFz>^t*7PNRy6Vc3GBD(8-wvI^jHDv!^115 z?}^bPn|o7~tb{5fl4SY;*$EG1DY*@z4>H+{y&qyZqEm}`krCpw3YPlZ8xbyG
S zm37fs>JZG8S29DEi05L)K9P2#{RSaf`E|o_9>09zzGm!BFoz0^09X5vFP4d_7}HgT zcO`Ew!Kirba>K2fvGac!@)9T~R0$P%J@e`-uQuRbH8Hd3it1^sN#^ufE5_R9nV^lN zhmkA&FHN>(T`NFZd1PQlNAk}am;t4HtYdHQ zANNbdzkT9tW?dHt=+EJ=tj7FTq zj$nHSMiI@ba>=+=l~e60?l{~h)9+^hnWedPM$ymwY_8k*4IPGOc?5Td8hrjWKAX zd=d3gm1c=$=2=&K%J7;pwX4M=$4X++L-s?0cKRyxu!b984JWP1*5T*ml*2??$8Eub z-BP*sh*sVDoV-i-$c6Ca#?1yrFps)#5_EMM+zJv1-|L7dsqgy zcowgCmt*4FoT|fNDr;Y=<9;gZzB$zM1EKq-ll{>Rf^Vc)gveoMS>M*{S7>~!ps^z5R+cXKCz8S!MKs3r{fe3d)tm}jjL3*E{Dvm^LM2*yeBY;Om2-0zQ zOM3s3^d?6HUec(?78%kd4hmi~5UOH-8$-5F5cWAQ4ELA{5uRfh1J3BP%dyWV>}+j~ z?2KFdVWa=Dvs+|&P3(c|`Bi#2>vcAWw{^eE$>EalxkJPStaAh2VX8`I2cKXiQId~c z!sTVyRBL!c;MxYN6_#!NfbgBu2ukMcDwZ$IDp`U!i)>&{;%w4^h%A$AYo~jB)y7h z{E6pN`rSSmdAE^$RE-g|23#NQB#~;kLtvS+(Tq@d4Mhk|1LBZBZto5W>@Rmg_|l4D zd(EIxY^7M?QT?)x-{Z~cLC;u59~zUu`I`rKp#O%X+{)rvUavRpI6*kyvkjeaGi!J4{1%pek@N+u1C<~nkI^l3z7wDRyv zd`~8e0evFHG}{LCXZp?;?(GS`>;5VKne!>O`TPm3+rk+C@4-+1&E4T-WM%m0^MA;? zFW~5Z;AsD$x+C(xsyqLES>V5cbzedEf0FS3x+uWH@?RGP*uQj*f4eB~e=P6(@Ad@# z1#$YHxVnEU@31g1{byWV+<)cjyn>Q}#GvVFBt!)~g)}b;b3WhvB>$+uF&V{nSDVsV z7t#rQK?$$F$ky>)#n8}8rPXpxFDrQ;uQotGhO-el8ia8vcH5J8R@qML z2}MHLLGAU}xs%>YTzAi_H=(gnMXu5#AW~R0zWgllAAv^|7v5N)>A5*+{Kt{>y9Ou0 z0w1>MO4FTH;B5*gIvbKB=q6+Fu;n2f%`z5|X z^-H?1dY`Y25BLV&??gsIYlwm$hgAYoZK8f$fzy`X^*wI|WZItOgY+>!@%dggJv7^O zKi4uZiA4;)IqF#+DZn=Gy$m7k?l7&*qr-r+cRh%)2|3CzFm?mTPWEkRwUhgt#kAC{ z=4c=0n|Im(RiA~-v$$?&wospcVr+@Dn_VH;?laJAAdI^5?P#5$+Ju4(kIHsDP;=+c zvLslV@OkYaa?2P!x{K-Om8-%I2vq=gfm-_T{eqv{*p|nv;%C&N4yE?luWGB+$=LweVysSc-CHedU~?2jv&#?=LrIi0;>HnxCdGkyS_@;sv`Yr zSX9pwSVQVW_wea42=fs*%qtm}pX0Zve5gq<7F;d}H<+DGsBc@KOX3PB?Y?0hlTjff zr|X2f60{K(D}P9i!8OKj_ni;=e|G+{5tzyy0;;>=okO*7-Lc`0fxJ@P@o zzHw+k*RLsZZ+#bMkBtabV(cxWL>2#0lBat3wqL*WwH>_k^uWv65P5`g53>Ji9zAbM{?`a z-;WR;^89P3qHr*TkHq{%0m&wsl^P_Qt16lmiA!AiTo|<&(MK8EX+5 zhXem0vWwLP4|xmQ(~@ROU%Jt_XjMtejRpUQ>6by_2unlz~2lCw1ubo^^Rj=3j1tMW64lLdNGnVV!<-fOk(n%TJ@CT8Z1ULjJ^r0A5S$TP0-S~y!K&?6P zS@#a2`sqZjDgU{-7Wbt!SlD%Zt(OiJrpuR#JC?{XARSH06h_oA)RC|0?Xj=d&CTKE zxG!jPhMV2eyXWI(_i69LgJEx^TW_JX+s7bb^4tfodIITY^Q_Z{_g3fUprhw_qTrX$;$CrNe4OW7)nXLKjV_M>Uij@_kH>7pQlJjT4awW zXlW-Vw7TBrG|tZps=(~N@$buC?SS7o`=-fVA~Mv$uf=R{8ZRQO!D9iqZ0L}^U38j8 zOh@Fw2M1w(Guor7x7+0k_#B{3?@%`p;~d-NhKkTQ5F@!OBI@L6-GxHC>+;_i@*k1= zY|Z`yUn zk}5PQqlKs|NW4Q#wBw_p6VmRfk5yxRUe$_+bj8+9Jzj?sj1c^KB>2E{v^9U&?7Rnw z6>e+ZT4_5NLDHs(-a9>L&i1$nd-Is#>BivQUlAUMlKGOCW-f^%C6ijo z=p8&*>*IgVHR~GcLqtR=%iU&2jpyj*T@e%ibwzupw7MBt`Q*AGe~w;$EuQ8N;nHru ze0k{wdxg4u+%=Bo2UO%xKecsuJ=3>0c|Q&De*l|kBeMUhZIZ7D(ck2-`PL2n7P-YI zCw@wZ1w% zUh=-F-grUj{@|apckiDZUBG#~SbpDVnOGAH5!?2N+VXoyVeu>}MG0L}ErSv!pEk;& zlJAJ|)s~7NbwGTDxFrYOKw&Q#3u|fehJrs^bKTw!Q1J{S@D4;dKp6Y<`gjv3$mIV# zGEvBkfZf*{u6yHJSV@$2K-vv}z=s*zP#4S+HQl=6Kf+U&!OGSm-UZ zDb)?(q%q?-SBmOaZ8MrY5zSaT*f3;2Wevn(y9qgqCUv9>7p$HW3OuPGo6=4WBMr9| z)NMp_Cwvo#W1Ma&7U;OLM2}{>(v+CjRD4=i&Ovh~pe8sNyl(+@+LegYAkh~8xJp=ZQUi@%)8O) z8Zb`ZJMF9hb~k+4Y#Hp_$%B1JxMFGMgZ#=2fIlx-irlv}#)y2j0Jnc~OI1{}pe%cmIdFG}S z`!jj(l)x9q|CYX73ALC8y${<;l9Xy?XEcUm>Poq3KCA zdxT(B41eDq?P&8vqoGDy61x{{r>d9I&$#$Jb~bOcUgw@aT7BHhV`o{~99>>S1FE*3 zd;HD`x>mW`p5lA`0H>o%+U!e@3rSE>&nBOxtUuM%9Olki-P=i^e72PxaOd$pK#y6l z?w=eRO^TDrm+LnKf`f!5U0{3rgLR1OHnvlC=G48TtZs=nj~0wb2$K1gO9e58Cd2K1 zyC-Y6Y*S*Io`9e8#wXXY8j}Xeta^~u-^*~IYGKIHl3cgt4e)5QOj{^DRZhkliW`5} z?M*k~iJO(aNt!-R`FcMmKDfZYJ6(mMk`e$ZsXLjLi)5$9b7m`Bb?S$*1X0h~3t8tU_F@IF@oKIKt#iPGjO5J|F9S zmNb!V6S*vA?f+@jauj#SB^pDZ9{_q+MS<#N^5o z*)!MA{sdm*&V&aeHFDL8h2RA4Y01j~<&$F9HaWS#1cm0v5 z1EJl>g-*{)Af~UsGxu7y4;hhSqOd3RG7W+Ek{*pao{26q6q0paOQsRR5$>prtQ|JQ zxgFg~;>BXVNXQPPa+>_CplgxFVJi{i+JPfY`awFavFTIYO||mI^_$!J52CVCH98Ot zUP78s7#HxVJDg-RE1FPLugYHq0x1bETx9pob`(mlc<#YGhFRqFJAi(iL3SQn(hRz3 z+n%L|#VKtW4z_I0%e9RyP7j&GC>AlcEqjs0Qqw5Tr~KZvsMyB$0Nb}XPUpks3-1f_ zRW|#se(pph>zq|jw(`b1zUgF;38CiK+c>4jFbS5OodGCkPu$YS;>)a7a@aSVG<7;f zfl|l0alUFaV;l(EG*1`!G1ou7b6(<^+Z|pzm%c{8s_!sp_m^?C!VnhvTxFqiC2HZuQ3_DE=mLBhSr3fUe9*&YdO)pISOu19_ z6Q`7MvYEk^Q&fR z9I}tri^myKN;p3~DVREjw{~sY+2~iceo{W-)-MW&gk9BOn4yVaEj&S7wm>|_;j;cH zPk;?z)&S3x%tUwE{2n`C(Tu@71AeiSJ2c>Hwo~zRCX7qbmYpLKnyk5hXI!Y>E{bm~ z#wLSyvdNgME+c%}pd&&{Ea`eI&^XO_RkZEz3vs`}oY1Y%E3tTNJ#OL-lTK>ax`Isw zLnTW!s@m$$RW+{BO!iz&?XiV8&90v%3-cD1&W$fz!U6V`-jVs68mBh?!?yeWq{DM; z`HE{LmhvePHw7Pe#O}v;*yTyn z=-h`#Z4DaUEc?yykssb~1p2zC0W0M!j5NzMROwb>6Z z&;9W=ZN;I3>h8P7Bj3<1wHJpPyz?>IPU=+*qAL zQL;<{fD}AYI2PznFs@mx$P6?UBSWGwE}ONZLF$3xNr64bLb20D6U!ggolP3tISVIF zT;9mpq%C)J!enU^Q|KnAxjRiXBG0>04SgMb4$PXC=Aza~AU*<^^H#IgUw;Oyn5Mq* z%Vlm#?@8ZGH(a=fK2x104@qm_?@^6h26hwTlwD0BO~iOM@D$(&NQ#4}k03XlvY^Kc zPFq_4L{!_38OFIcsnqeZ95L%{zw&zz%KQUc+OfT%n3Pk4Wyy>OgeUT((W)*$T^Yip>no1HPmbpWz-i1U!I8w8-M2J-O!$aYn_*X*(Xl0-spL`xzUc#1Cq&a9nbe{ zl)$&_SNW}($?IjDVDtU_()S}j>g%cLW{Uo6dejPTR1y#G&OPc4$tN3*2+tvprCTB< zsu@bALmDA$Cj+87X%8aM_p_(u8{-e@><45>PS9`&C&FyCX-8&7F0b!baO*G$YE0UE*D zYct;H#UQ7gyff*nKZz8tEaEzr$J{0J7-#lb+bhDt!gSSUX%YgwGop>KnPuz8SCVL! zk4;t_kR3Z#Bt_SmszPZ`#Ze0EjGGRvOkid%E#0gY9Icc+HOI z1*&T%R?Lm5TC_x#(z9evI9-wLk?TcRObD6=iz%4(e>2jx!7e@qd~AJZ;hmyglI@d$ z__w@CnTwf|cvW~|+#TF;Ho4YS!jaa8Nn!^DVq8mC?YvL98#k{lH+(CNxBdJZ)UFqU zsW0W|Y`i_F_bUOgWEL7c*n*loKQzCF6M{9lEfx>A#T2v0>}XD!4*sN}bp4;RE`Q892wko)hdf;xnM>qCJy* zlJt`p$Knh#VXfD!UU7@3689#h(`?ghvur7mk2wEmkHwAN7ZxcwmKKiJ%5^W+EV|V@ zM_L0|46R?#m0=yvetwnAm(y{HOvBq5!xBmMYFb8`M)tBxGrm*B&aC!3h8py=^kzP;5RiGZ$g!TP+fn2Kla^On!1q;O(6|q))(X6@$RA zI2GZT#J3a}CFolwprh0=h5NJYx;uUF{A+slCaa5iOXlE&TxdFP54|^h>V<1gj3i23 z2+&btdGMI^=ia`f#0xkDe|--;7S6*h+suWeFxv}avXA2YE(z^*>U4eb^{(*Dip$w-%6BQD zn|pGrd(-_{=P`S+34yIPA}klri&phh3E4vLX?**p2&98UVn7nnYYeAHNZzt}ihBuV zk9pLjV&!dxo4e~0^0b~@z}%)}O|bQea=3f-Tr$evXZIhD**&!U@0+9TNjCFURqY3d zVXmk*c05aygqA(Adi_01aUA)ISY(n-kKdL?)BUc|APmgI7-&w#S2lsEfFkjb~{UJQg zPXhc=Z$$LRcc#u2)>{Z(?(CJvK;4oE zNn44_##_`5GMqE&cq??Fno2UIt^1lh#(43eW>@$2p?CFT7wj@(Up118XeRt$#)4Lx+qzm~&dsN;G5 zy#A;aXnxtx?aJqM9WTF+k-mD3_e8yI>Ds{VJhE~_^o+!rzSD_trVMyU^(%WTB_pp( zQ;dN15EfeIF>_3l#W(7~kDN3>tlda~i=_6xFR^MkMhWfKi=huan+V*Ja4kM4axiTT z=S!3{g$Q%ytQEsiJ65WgC#e7eIhG!fnufb27)H2TB|e`3PY3U7_^qx}L|qs-f0EvI z3SIZvdF(C&y&7PnFFx-!!J@b1pU*`lC;~qw0#4rQbJN!K*G#(lOBQTNkaD5Lan~Z6 zNoI^1k1Mc?7bf!I+It5JXZOFMCER?VJ709vGD@KDu%mkKf7f#L-eG>Ccf4eJ0A8R zB{CKZnl_s4MzpF9iVcYj!$XXY2`EtQ(R^yYp|(-5S6g*;ppNwb9&P8`TXpV}F^C5B zL@@{lG4Ra0Jsfw(n+DxNfqtzcp=BOEFc)8ydWs~KU>*p@AN8Y zG!=9@b4ucZp8Zd#?%lhtl&>;Vr$-7>tvnnD$}U~U!b4blK*L-F1C_k|zN0Tko>Bj#8k%!{$-yqmD(OJCOL~dOyKrU;cDS@9a ze`vMrrq7TT?=>}Y#w0-K!V0@u$ z2V|et!jp%imAX!I9wG%zjm6GCSl*S!^=&9wm{rAirvR4lz>wH1=9pH0{i;P$LTvqc zz64bZ0;~vT?8~7%kzQ*2iWEg zLx4G_-`r9J|6QIJy1JncDmeeF;N-Y~@yA)}YUt(hlY{7UYN^y0k-PE>{^uIBi9W42WpDAWwA-dNo|gy&xIV}8V>j9R&1(p}9~-s}TRxAxT6E{dHjigv=h3SuJ|1^^ zzJDEf4_=A))`D!V$kQ5-q~k$277dcom=ZTCrUckXZrw+VDkY5LZc;9njyx@R)_6jA z&yvCZ%*?5hB~p6;EXrbOhqpttY`$oSW8ji zc+$nz8KQIJ;c7pesXV-%SSLz4JvJktV!cr>f%2MM?>$c@qMH(BC7mgsh1^%}JR^&9 z?eKfUz-sRpUPBvKYWbAORF+Bp%60Q}twu1eVHD+1MtmH}LBU}G?K}n+Iu=GMdTKb0 zC^JSOO&oe5dLgY$HG>MKS}N5zwK7$~pZPxx&cV)u&PC3L&a-Xv&gSPYa>B*6bMyKa z62Js5W$w8?U^*Z@GF>)(LO5xHGQDu3G<`0376UhxnJFaScEc(QXuH8w)Lo~x*>+uO zu2G!VH-eGHxAHnZ*6o9=Mc3qASHAQxAC3S1U~QV^eGhe$eGtvArvaV0y|=a6S}dL&za#PnWiVcY`2J-GYE-QC?GxVsbFU4m>P@{>b-{LFP$%{n9Ccnxgr~>la;s^7 zh+cGnt1Qx#DJ5fJE-M)zW8dUkFqK0={z1YWYiL%d$4@HcT~7 zRz{xf(0!=;73owoX{4A$y>Tk3^hf2sb;_hSS6 z%{)4ooZC zG~~{(5;MCg^2;pxWG^Dzgo^q5l}8{&qaKRbrxA!_>M-QJCqJBit8l;aRPsiVntN0>ln>aZ_&-#?nR0Q=w?4 z)jY%@LaU;1c(>Z>oi!oyhshlb*`Pw~Q_;|5cjtNd42m9;x-{lXY%xCYX(OnVVIMT- zr;3aH64i0cnv~>GtgL`YX?huNI5c@aOA70&X^jr;s=1|#A0jpZynTElS!NRsI~+GWT=Ab2!Mftx(=~ zHnw1P){LRu_p-^g%`(cW)6p)ZaY^J>x59NU!$TO)VJm*cmHvUzri*?rjH~G#qG$GH z=f+s7jJJo{Iok6l+UKh*u0Y?xG!9h0n>tMTY!0%#H72gU=?zZ4wr%CvFXQXCU%Sp4 zdYuNZHr* z-P{DAYF|&BZq@r+O6^fF8rF$m*%l1g7`kn#{Gk}H@SS1# zxLd~5DMvN27)YoN7;nA>pLut$6ss>rdl-yGrV~b-zf$;cihnp)pZAt702nLHJA3C- z1Jp*kLe(+XVJsy=%r$LFgHaEfsf;5!xQ_F!hs{2;K$Y zOL+_=)``jh&R`v4snIevZ)r?4B{pwK%-9|Dl-1#4KqY&xMfjj`SXBej7key9!?%d) zMeyrN16X8O;D=aT#@p|?$N|2gTzdu&@3}Da9}>Cd37gKMxaMca{S!thGf|#=+E1gFl9c22Raqv7yLF*8h4hzjdN`@IG)E4@*VD;xz~#xFfcE#(q3ucn*6 zT7sN~r+f5X69DvLK#?f1Y$berl>MH&hxI|xc@>sk64Elp8M;R$=72ab7t|Iqofw>m z+dyrN06R)N_xc%r9LJspS;Yp_ZMDDK9NzlEb%>t}|${7MPEgLFgb zn%pb}X%LuQY8lzC6?CkRH*Lh9?WI$>v~rlCfYw$5I51FYI}wNGUXXWwRZrsr1SDwi zqCFLBQPK0`xmk^rx+1(RlkgHBokcUV59SilVqa0iy>gZlv`0sA(alVejQV8gw*MY2 zYwwUyNiXav8x=|#TCr5dGQ&MA=+lW%1V~_9r@o3*Mpz$<6t|DCR9vB}A`J6G_$l0o2fthDo_a__C2c}DEaA18E3h4M zULMLTH)z$6nZo@f7SV2oT5FbRNs^4T7#wOsmuYygGZg4=uq}rl)L=eh6Wdtt1Bhh4=ReP+M0?`PUv%FNoCSBrRowR z2D&b?fhwAcs#72mxR#4b=&GWcyrRHpW$Lvk^pPp*Drzj{7m~Z^2ygOWk;4)ha({3R5=xu#q?F+)F!GXgb;+(B_+D*>NSQYfruEapYr7`i)rZT z%BU;bro=hRLF0}{q2gcZfW0oUM$pyis%@@S(t10ku&$u4rXy-l;;N>yprVLZQAtl{ zTU=a{oSfoM**8Kng7!rqF@AU}f;wA8OGmZ+W4TW}45V^jnhLaT^~dto^2+9Ein)d4 zB$Y|fgPM<(<@x@C0mp)4$f<8EQQcpZX;I1l5umQ3wSXA7~6R8PCcDbs~y# z3o8u*k}_xxN4%6AbVYeha@#AR77Km^p{w-I<;YvMTPEpQl5kyXo`6ucYN7uOt%fwO z%*F@)>WgY)3Fj9WEpTLg_Rcj&R4F|bD0ZU6)W0|9 zHOdTX%UwHE5;Z%tilK|xpG=({eh)2ZZ$9iu)`R)O>RsSwjQv|I$JxTwti~)JR>ik# z%pXzA7d$7C4uuV7BbF85CCxD`#W?Nh1#a!px{F~6N$cO}8&bk$^PvfW&IWq{wEbH_ z`7p)$icw#~&dF{>)RrM-3RjzgbOwT02owM;q2a9*_yt(NtwE~mnIvHQ(YhcsS~uIE z_0vJ@ur^3F2tZpwT~91|uA-!{8Wl!BslhVhC)%FhU05wr!fnIk>4L1j4aJZNeCDC0 zvyLWql9@xC6ND$#2s+<@DLn-T$$n*z%yI3nLe$t8JCyy3L#VpY3$C%5Z_D+z9Pfa) zbQ`Ho6{a3tFc3t#;@nqkq2=2%lul&r$2yRx!t)2sE~cE8=ior4=abVpD=SZ>z3NiY z@HIpLt{Y>8>n9xu+WT1d-1s>rFJ1VR{A;S_mBo(t)ao>O(_=iegQxY?ZMm?P5y9wo z=Zu}iQ9ZVeo#I#a!9oz#{VK0Q)6^+zS<2F5wxby73-8@Qa?;a6FN+tqu_)`i+qNW$ zQe#W;Guis2r&D(imI=AVvGvBP$#aH_ZuFVmO)z^FEc_LV4hQPU-81tANHWd| z0yPvKGLyBYUU;9h-!?|n_9*Cc@3)#x9IE^&C8OO72NC*KJsIN;2yXQ z?VeGoY3t&uO8C~zec`);ZX5oYT)PODgXYL3X4@B|t8UBn{lU$Q_sp@oc;NPQ6AN zgU<$Io{Qz4qs4AgV9vuceiN!HhgoxAt)LDGV)WDMN@h$n0q4e=`~d1E6$fF;qWVlD zZFX_?4Z!6?ukq{RWXtry6$d@#`ds7lPnbW=uJV^VBR>Gmu2O15;Ym*nTxfEn61ioS z_3D!kjm-m|=`p+wFh4B7CAKde0)|YEa9Z*80!HW6mkQqm9sUnYzM_ z`2z(Xld-Q)qRgrIl1@Zd;1*T*ruOvc&whjv|j9 zU$H*$AoD=*ZWeup@dqIG*zZJb&QMDCn`vuD>+?-lTn(RIDLJc{p{1^M+T^U1O8>!Z zj%D*lXUmOJ&^7o+W4tzXP$!g2Cl`A&1f8UAYpObF#x~)Tq8jsd?0z&O1g$Z9DvraA zjIFoO%xF!$m0#zgLG%!s50;tglcy-bt*_u~V>T-TmZUgRO6;9QVMohDthnC#o3ocr zmW8My(7GOQ4M%ocfRD;6eHd4T%){C*hpRjUd6v4eW!$LLzoC5QE2QG8%-X2a*{x6g z8fI9?A?=qZcs@ovI*V!*ljeGT?Qxj2p4r z(f8wUA-R^_v1-h>5o!3ASi!sB@aKr<%yuD+*U-um0p5yjisRDQ1%`!jcUDp;18i$t z3+FK$!RRubOob&k3dBL@{8Yh){)Sg=#u4M>6?zp~O~&2xtfM1*Wl0&Dw8@OchNee%uyl!aHx){p zdc1u-Tdq14cV=S{W;0i~v3VS;DMNU0l^ox{V$hmAsgyWs@aIPRMyU_!nkX!!FZocg z#WfYFAD66c8>@3QJYUKVH7Ij~lD(?Zuhv!nEIUqpt68F%;F(pzyV^jl?v+x0d6}?g z*M6_y*i_4&zWfNKnO%7qFcn@YQbG_HK5qPe4QPQiY+D^ED6@7VimfYJ>*LZl*PQso z^r;n6ip~SU#z!%@)gyGV=deS_hmC!gXUA*(|u}( z=Pa*kszvILgcj;Ad}!<0vWG#I0`FSqT$1J}I${mAgDQ`OOI~Xg+2gCwRq{~fu^>DL z?_0f-S;spaGU9>K+)o*4J;hJW_@elfw;y$QLNS?il6!T4<4e(O^R)gfLte!(IFg6m zJtBBsn@uoA$j_RP@^%#CEnGZi-OyKronX41cO;w^q!YYHXjwFb6I?^#VCP0@Jis7C zLpz~N@3hF}qsx)9T1CXv-cy*I_hOubr+KXlbzV11-ee{4*b=YP5k8}luBS=HV7#~E z#X##MOBe{)$+)NMW@jFXlZD!pAm{WVd8a}eyAv<$Hi7nfXa^TDvYS1AsE7F7L5`?9 zWx^YX=0FU`$q53#VCc-9Pi#J2!QZYg^d?B}JJT7yB@6{3as)v$4}p7*b%Vb?{{;K( z`slVpj~T{u%=iR0>H+;>0e;7-=$1E*t~)DX=ZQP2`;pDDD|;OwZ!L1L@?H+E&De3h z12^biF8;pp?D|Ur)oPpn>e2oQXy@?|soP0CtlI>sTXwVKvTyLZ1<8v4yqG4D1_N+hXkOYNexa> zun)3{;3e{Xp~63ZT$DjclFXLz@EjGYlJOYLAD93-S3RyQ5ORb5swKt6EhAJU!PRtz zM?Sr|zv6FvPljU4O%-G^J>M#5&MmpzcveA|CUgWfeYmg9Bnjgulp+C;NY~AmBnM4n zu^mOnF{x!tS*1=uV7eWS-bto2?vR;Jif>?Q(ImH$1IptP#CR@>mJ+|&d5z#@y8M2r z(#XdV$%43YxcCT`4+=He<+Ow}VU*?e?;W|Rw&8^|iK*xuU<&Z^jaw)aIR?)S^Qv`7 z`+PbStVw-%&y;!RFGhYO6g=n{SfIBUgey01iq#s|2x@GRNH=>~UU?C6~<-26on?iIXHZXlXY5hfgbzCg`{i${ER3gJ#le7jD{ z`xJq5xr-KN1fj~v9oy~w!@%y<$6odUsvBEUCxI|dIi`V$38;B9Xvy(%FQTHzvo$udM9EDB^yLUm`R(Gvk?EtJg7JDm03mcD1f*OQ zvXh+Q^I|MQ{y9rR5E>L{Nciv1oL~ue;UN}KNm0GPpqozmou0BEg`d~py*Bljgr0FH zYcQz)#V+Qj<;KrYOiXNSO#iXx0!E+tk9+a|r#+YGFZNs}juxhW*>U|6hKc=W6egfC z7voFx8%8D;CS3+eX9H^sBSBj;Yv8wXI0iu{BNJO^U;rDAzdJ~02AYHY-9b7F)4w}N z|7n!+cSA0q_v`<>!JlDlSXlo@2k8m2vC9CYkds?xllOoq%!^ASKf z?=0WjG6GCxV_72)-xwFZri+vxhfZT2e3uR$8u$~8yXyh51K*+#7L^JzJbW`&#zS4( zZ>)9EqBT#hW%mZ2x>~3UGRM~@*m?`t=;`37(g#sA;f_AZZI_|w#Or-da-`cp-$rjH zw>o~cV17)q?RgsFP;t?JgVAoHMs9Qv=Q#l$UOc(g%85IzrDV`zUv>j+GDey7l6_jzyo9jwZWiy}#;N(m&EX zh{rsUy?OIUv%__#&XJPm+cHBgvlimo>v=n~SJ)Pcq^(1c^nExdgZLL`{DW6>zds7T#mdQoIL?E&Hzl3&=1KpK8=)QNG3HcC`T-H zv|~tyiD6IBJr$=+MU<3}M4w<@=}_oM%)$bq{^nDq>T(|Me5;jqS;JgsOk2@%WpKu$ z?|R2Ygde`!we!T14$}qi)5QAonKyf=IS2X2H!L9lrsl^=1-GUOJfce`A(=Q&@xasFBFw5bLiv_AkN7YiLtQ8`CNwOp8k9eg`*aZeY#V?BWP2yB7GGk7bUcR-Iuq!}!Q&3cWq z$P{$fvT$$#+L~oaZY8{Gg^e@G0^ySd`c-_#r7)ys+s57RDlVxI>}1V0=vPW9iXamZJN~CT#~pZfjUG!P?}uilOQD$fPw|x8q?a z(lmj1u6+!`D&{R#JT`4l>r#DGuZ2LmK6Eq5BxsIOQ^wO#f-lFDqWcEs}B?Vp8%CW&w z%Bj&bUA?9VUWN{?KD~>btbMyhh2{VYj;8&m^UVRNVbY&CL*yk$u6d>m_o&g@sN$iI8>akn+LSmS3u zy4k{HW0MC5^ykJ_gtVuEqv~YYgQcK4q=`&eySnrsWwp6)f2U}OD^X6s=~u2fgKkT) zF|x{!WeG+om@^}1klQNikcSMt2pj#%SQ1(R(mreukCZl%Xp(FoP+3#yph_Z96m)1hRyS5paK0I(Bx43#o{!S7lA>P6MZq zbEp*e>Q!x+(mkH?I-YB*?|Km_HtJqG3$f6E!iV@NianU^@mCtO3k$E-5Cs@bT&|SA zde9A{mTXEif=r$j-nem>xfPN%g$k!!jHbcDE9lbveQ2I6GsV{e?X6V1mA1C zsDcmuaywnZ8WqQ>QP7b~rO;_GBdeYM8iC*Vuziq4!qu5-z2`z)n^f0ssMTO0Vl zE0{U85EPU+`R<9M&I{$ zP1u^vTFrMne(RFtPfH+KVmW1f(I@Lmrbc%36c{|3xj>T{>ajYay@gB1C|nj=QN z{4F_xYVc@Nmx zflpv6P-&Rzqck@9a_zFG5gw{v9`~KogJ}w~d(^)U*IWmDcrUXyTJ|~S0e$*xe*L+> z&SE8G@xJTKxdoo_I(M_jw5)d)4~KYt`W?3L$2wf+_`6~KBsCQgZDe}8)TL0IGri@4 zuaX~2V!rywKYVsU=s~cud$+O5RBdFqW6oQ*xrnNQoNlT%OP|6wII`3-f7-V0@qL9& z#O_U!OGx4RXLY9)Nn3&Z!$_jroJ>@%LsYsrDv$gf7K4lOgYeaK-)N0q#-#W0)q<#3;omAtnq$%i<$hn-ggWp}OPeD=@7t9cXA9B%Vf z209c3)E$#dy$3!&wlw#?PlrPn@Z%QCKfaIT8x)N{VS#2yIk7e6lf2QE?6xbGBlTK3 zuGwCO$=~kF!p7E{_c?@(KZ8#PZ|;Dq3Ah(=;Qb_;J~kXuswFnzXQyI7{xwduw+LnI zTi>WPr|QjNBhim4-?C4IXH$&O>UUG9vDsQ|y%9D1r{!mb+^@^ay)M;;+yY7%KKPy+ zBX_xPN0_vJ@4t;a=3NH5iH|lpmDv2)SD{WcnpR_g1-P-DWs;rYIzkg=SCo*a=$ z>3GO|OHcL#aYx<9$NQdG+|pOz;?k)V4xvkyAQz(w3OekI(-m6GUT6M-GafegX{cxT z@o8lDBRa3g&$pzrnJZ(M{q0y)F(6_s^Tln48K$AGz3O~_evZ=L0i&Tw9_cfO44>?{pV zR<0SMD`Q^dxd^R#*sXBrzh3pet{663dPmd$BfE6Add~NGVVUpzAWn#7bd9{pCCLUU0IzB10v*zJ zqv03TN04T6$}t$5=l6Bh?Q6tzOXn(^KRb_XwhVNc-AKF*BKX zTW@N(kXP#6!CQ*Bw4-v2>NhjpfgViI-oom;7HWP*>p|fAL;qy$tc`Q^^}MmE;9SXM z`A#riZ9hX&q0T0xN~UW;_CU96qIOhrasL$I6BUlSH;XrO)Q4}_vpr*i+pC#hyBy}s zGrhq%{VP+vA+M@E6=DzNI9zZQ!+1kws@Esz1)MfKefJB)YmRWFd5>c6v6sTlA(RH5KERaOgMW$cism=ebmimj^~t#7L7emFcf_O- zfO33gP`9}jRlpE_kw(6YfRI}OC$+;2Z5q{`6dsbq7&79hfn5i9if7vMd#Yv{2XT&} z-qtKe;w_1)%Wd?{k8%RW2kBDoe^)Hnp^c51^XAHExEaZ$RNh}KWGrB5=FlvWF>udx zJwHm7lHp#^Bx)-Dn;o?gM*n^iBlIN!^)|dpQbJjj8Ig@#2h+Hil~ZeygRO(=cr(+u za8}>Ca=(4su5^+E(eSoD9L7UoX(i$G>SQAh_k z+u|ZVs&dK=P5D*WW*9rx#?d7W&aQWB2ki$FLM)KHkNTw)I0zLL73lij;xYuV{oS?> zgjo1!SD=i`QbS?ky<6g+#YVOpVjDg{)~oF4?RGNIY*vGk|U zrU*~qzHJGE@Bkq0^ERs40Weyt`YgFo9wLwqDJyuFp?;Z2BD{on0x00fAR5v{Q}ccR ze>YKL!KMYsI}ky)Q3j}wm6SDRpN_zzQjo$E{oNp-Ka%*hG=^xQU~2s#)EI6(~QlWrXocMI+X#iX1b5i2;k(`^g$@>Mu}?JoJT z#Y<6w7t2o}g-~I_QnV5csTd=MZG-lauQBFMh?d-&)q zsaYl=_}+N|Oe&GcX5>nIA`Cf{SDU+?R%xKLLEOXA`{{VWAU{b%R0d?^bGbx3EZC4> zm@3)XkI4rycBfiOty*xnB1OU_X+FrM;S$k;Z^BTy1HJ?qY>iW@Ae_Jj=k)44^2J#X zJ_YVz`=2#`Y#%@e4L2mj!&FEawfB#Ogy_?^@z9$Z#(zsy8N#-(kB1^-fG{?d}{G**8)|~C0wv8IaNp%AkJMMSWFIyXJ-x~2F zhpe|6#GpqTxP0pRmTZq)&jk$FwLWOOYtz`(+itRJm6PMy9e=OQz0G6?+mxYYePUQxy?z-lc8v^7owRK7Zz0Y4BY$wTg2kEau!|r-U6;Y z7Nkvj2B9#z03j{dS@HKQ3CMOqYFuvupK=_JMRoWTpmboV4^rp}szp&u3o%t51mJ@^ zJ~5&E5X((Ft;8x1>1a#J<0yZl%FIisWx7m&K|;h)(#|ciPR~0TGW1T2?hI<9byr=d z=(HuzYMYm37*S~xjN^3*6K_@LmUo3~FZZ{KE1}rs62x~x4N`gSy)GyXIfQVzy7mRv z9|d;=72Umc0#=KmI*%qD-46|B5z%-oq0%WMKG|V~4+cL-K$l^lfq3vnMGZnD#(sm< zMCL->)P~5yJEa0Cz)90*fk5$4fTvs)I0B;zOpFg@jGG8d1n~;-DPT~ZqY{aUK$y{8gE!wdqI8y>P#JnGqK}`CG4C%=qhN&N8}GS<-T<$F&7`CVsT!bz z_V6~+auXTt4o{#8x|Pr?6!cZxc?gxI$9p0$d8>$ej)*gJA0`juSP`*&WQ@=KggBsD zC?n5lFmW1X3?-WVlaP5T8T@I{mY+^8_(ksdiF+8LU8l{e0*K|Wby@m-A`SuNkQU>* zOBh?4m`VFZ)A37`BR?j270;~RTf$DlqZVg^w$hN-4JiiCH!RCcnlBM6O*mWo-H|-J8efq~BO{(n3x~6tX7U84 zVFZDPzK@?1dhLCZ4>g&T+tv;Ir@^9~v-qHBNre3K@JGdBNY07yeo}H{GKg%!Nt8TS z@(Sc)XvK7^$7rE>OZ(*GOcYW7 zxPZQeoo@zT)%!)hE8%gwu9p}tEA*gcSBYo3h{%QPZNN}v(4&u*_gk%zvlub!SZZDQ zw{di2sc=+`@?)(xx1#lf?tKCgk>`E9D8&V&Z~f6&p!{Rpw-x8Rsd#5a>%_;`nq$&# zMEK^4X7MTVO;RKK50o%;mg1egnH^dZqq)eA`G)s9gwzpf@Feno+|KOus}qNhMlFnu zDvPMxeMrUdM?OpvxNS(`z-)l+GIK<_yD2G?9b#*7^av9-g#PBi z;GY`is+0*XB^tUBC(nraz1%Q>g!QR*OuZ5d@%tsuV+ir!EQM5)?TEs1B074D#Ya3k)RRZNACxo z#Rgj2)gPszMUtEx2>n&KnUs0ijDxYKi~`e8Z9?wzKOAf7M~B{L;<**C~{(2fw@$BFX}#4oN@>VWPvWIS6=#1y$rf; z8XRL^|4E8{bf_62Zl$<<0!~Lxi#sTGky!gM=qi8Sxr|oDXth=@bxF{tt=0-+34=Oz zu_{j@u7=gXtjw?^&QOFDHH}VR5&A>iobAmq7#DQkjD&Y`MS~K7mVw@nJ{h|ABt+V? zVC%X$84C6Ox^k9~Q#&e@F0;a0vEk>a6}VqZt$l>6U491Q`@5|vPO{NXz*&b%cZRzLXq<_U1jN4d>%c(CCDG1&Y-4df^SCkct z2-}X&>MbY`-&a~fUYHbnWLD1SqHF-SX94dZt0CUc3%*Zf=rugi}Ad{~*{YR8?*P0%ov^166yaD9t@^}%!F%US}^yPj4{}# zkoMN+>&GU@k93Z(ELF}zV_w4WQx|XNnS=%ucTI&JBB|<)y|1I1woap(O64O3S5xGB z_+_^7l)jX-qZv46&(b*dP(Jx2_XZIXKD&(YlN=6xBblE6n0BoY@L4}%Hvq-qmcc}% z=&tMRx4l_S(mze#%D&g{3CFd*R<~2vF>)tau1;27BV~;j} z;_0ito7D^SRZh@s=IROcjeWTcK{HEul1L3v63e7#mdwXDN1iz22JLhv3Kc_AIV-rEd>`XQ+Ar4UH)#)#tlG|1mO2W8#&$nn?*cHPa6(M^x6^EylC z_=};}37QeWxaNAbV()mU?^=d&P~YH0ZM$uvcKfrU?E?#+y%U>T4iW*N+U@f}WrO?k zhoY88lujo-0=In&uYIhxlNc#mJ%TT0`X?Z5$Hl!(>uQ5*oiOWstlsm0u`g<2*8zte zV4W_UohEEgTM(U`xUsNc?BtsnUXZJ@7pItF7tIW_n^Qbq+gV=6{f6xn1SeUa+ThOQ zSn-!WJCP7<i%I0N{@x{-27f>O2uiaFsz#Ga&sVmsf{k7!gtwOZRbVq!DE4FVyE@Ux z44^&9v;%Xes&t#B4b4n$^y*8YG{ce2aM1M7jpxKVw)zcq_SpO>G)FxTTS76}k+*f< z3>6xikr?oeFiXye!L_wwF!#10(cPcgcUQfjv!Ips=?0w0c%T!<<4(VU>3p2BC+pEr z))}>6(J<1FjC4SrME}qq3}TlX^lGCl2YWy8@fMW>@y9u7<|{DA{Vg5v43bUjRAXE< zL?hP8VsVFLKQj{y$2t~{IwUiD7oC2}J-^tp9$FZq6a%DEC8K`-xS%vDu|-eJy36Np zh+Sr4SJJ-X;`u6nHJ`coD>wt3#DyCie*j#_puEGkB4pe^sp%4cu z%3qY#Khuk1{6(?-Q^EbBG=Is%{-Q*Odr^|VD9-;rg?&5e*#5D#eZ7@LsPv9pBjY2!Lt7&pAw1lZOQ}KLOdSe;QPm1`Vv95Uflcb39y1A=t?t zS||%?JgXs+1OFTvOdVX*;puSBdj7R^*RIltPOwvy&y=e*Stv%qYh19Ve#`@<3G68# z(9$Z|VWrC{A+MlJqNCC;xYiLLHJz~%t-G7$(wE5 zR&0adJ2+m*TZkp%V{r|AIR=t9JC|(TC|4c8EYQd?n{Vu<2jH&snD5HDQbxwgfFPgcGt6!7#~#Jv#akZ1MqN+lGa!vhUa*vWCA(9;#}OmvIP8U^Sy~|b9D;q zQ0puES#mFKCcZA#Y58R|UTqPq9Dxl(tDezAH#U`EZaUPP7{`gaa0XMc4<*w3y+174 zV9qh!*NKIaT;5d~2KJEQL|U5*sbY$PUtKLzl3q`6hZ)pohmdJX)q0qpENwd%{iyL- z_R~!(kj&y$UnIB=>RLw?UM*?w1dX_~$@{l?|38A3{%xlJbu0caWa$M~#Lmg`FT3T> z_4Uhc`E$yCLHe-#4e2AsNXYckUnK@H;39gFCcrypLLltu=N%C7^ygDnLdHMufM}&Z zp8~h_pENk&Hu{${dEklUKU?w3X@&4-Yrr09$QxRk7&-IsFi6_45dKk@qzx<%A z5r4jcl8KX@i=&Z=6XDN}DKW^J7+V+!*|}@KhzvF$=dg1E;f#W|wsy`=+HgMsPcOqN z?r7&?53E+1LB-L)*2(^*PNR1W!paOHCaxAnCQ9N$43dP-jxHvAd;B01!>aO2`46Nnk&uEsUMC34hA6mp_H=T!2H$__y)? z+i?FJf}d}~pzLDk{LbElLB_(?ib2TE(b&ZC=L-XLfsGqEYqK&k(gWv_g`Sg;m7N(l zHuNup@YgU38aZ3o*#h5PRY~$CQJOnD+jB867&)34I9s@y7}?p_*x5SK+c}ys08yYO zwoWEa42JLMY>nug3>cW{0Sr{Y9{#P9EdM+O3mX9OqjqM%xdILd;m_p+$MCY({n51c zA1}tb#F$1lJya}Pw_{b%w8U7XGB9C^e<#l!#r7C``jjS-lbfeH9G8xsHk z`~d)&2EYdV1w5MkkvM_ZKl88yGXPHmzyW@F#s5^r$_@bhd<4wO{!$EBoSg}n4Y*c~ zU5rfr(#hkoxlPw-C};}9+1xbQt!{^fnzUX z;A}!E!UcT94&VSVGXl}C05&=R3k3i`@iMl5ahtoNi76ZqqR0sctm)4WAsZ_z5X@&v z_y>)Roecn7BrhLA+dpZ*`xjpSmBz-*`a6vi2t@oXAICpwKwK~zkdOaSA1Cm9_zxQA z3vlsQ8XG%1+i(5jdPa5k#$C-thmG!r>z>pdLTn8*H%)oQ}ul2FAGXnmZ4@i4~ zn*P!*aDM@w>;FmPc-fAB&Bwt61i}7FV`Bx*`foI*-{z8ymF2fNVq@j_ZR~+O2}H2} zqYXCp7kTzeU)Wxl<~JHA>+frq=|#N$S{Arb{B!Kt*jav?BOq}01^51ISq{b*Df<`A z+0nql+QjiiyeV6Fm;l+FLCMYzC{q9YN+fA(YDf5U9|X!*NfAPALLNaORzVgHMh;;{ zPJjrIVOUuJBAl#jqD&lO9D+=OY5uZ%lZ zu2_*|ilX9lO!TZUWJAS6-9xQIc`(d`jD+^aRxrH046*<_a~BIjmj7my8N@AZTmViC z;xh1rxQ)v0q>V*urLS9r_-yBMhnlf#P_?K4tHE+ zTqO}6jNRyk%wK?PD)le*y4v>{LmRMtwB-4)CuR% z$&J6j*ID>dpMKaM$INOSd@TKNs*StH4*~t`;FB1hb6kW-GI=3b5$-0|5K}DEoekJ9TQKAzzp4`Y>596Sa3wIuwjDzZbq=B2thO+9FLDMO zHgW9M{YmeQyIltJpG$KdH`u-HdmQ~Zy4=4v=>57odcHb3Ny}5{%lT~79V^kn z+yQ~kCu1G9cbF+9+K`;fTr%+YeY->KdtZ9mrLZY20{HP{JR+W0px+75S)&F>FEzvB zduC4I&LJHCH5@k2>VtTVIJ-&ci}I{ibeW1610-->_UFKz#>Etalg_D#)03=QSSk@U z*-Y5$GW&&9kerKIA!}ub^j#Vo%$ERjJpf9j% z;al?z735ocfVvSUgk>bumo&*eHMvftnmuMr*t>x;$Rdm(Oe~+c(!3%|u50IXP{S0* z=$MjuEn9ZXg`IKgro|9gEUE~!Cf;ZfSa;Oc{0Tf`Rv8f6JX!}J(d9(ck}k#Z7GMEe zv=~!p&P)arT-g7p?m7})jPN7^y$HwSssZD|Ou`(pl^WTWhojOk8iNd(4zdpj9*EWN zU6b#uov7J0Pt~-sPDU2bP!zP8O*B`}^t;Gg^a8H$z#ASdWzmZ}w0vr~j6;Y#8&@-=q&0ij{@9>sDlA_o2`Ug5HNW|TyzvBl zHqa)TNN&E#L+2c&O9%9Z9M^Wr5U6)#+v?v={jIHUl!C(ijYMvMR*wERs^0-}wH=F1 zsjY96PSOT;n6TR}WRAkXMu%x!WXm5TGq%J?Q(qpO!8FEQ_$o=O22+vPTG1Lg zcQ6x9%dqu5Zyv{H zY$Mf#DbJ^=A+=d4V)rZgvOxkzVNvmJ>42WDF8y*dggev_ zvSFCV+G1P|K6!fExpyt$!|ho((peiR{Gw=eFtth?qk(n2U!M-`fu2Plp}2LP*F5+> zMN+&;>AC*;O^;#gZ4-gw{sdNRliy-t*swvV3qhmS9z)v*wp(Arga@s!btJ|2apbJ8 zbEL7wkT2#pH4v$wNhcGJa7{4;EP{i(GR_l(JjMC4%DQMBA-4;bcq~16+j{82;_B_! zGc`B6Unt}#l4sl0yR|Rw?PRX85i=6hU^HgJSlb!9q8sA;C()VMS;n4ywSC7X(YZg! zHWt3^q{&39W1YkGD)tk&^yXf{h&sVs z)j`^_dyDV;2)V;kj&`iDNmqBNh*6q4?bcxpYk}=ky=0&!;W^o<%y)R}6BUtY1^^0I zbR4()FS%vZb720$ugqB>3LQUmSl6)V)kzaxqqaA!-2@V8`? zRDxawrx#Li>|NqbJhWyMbP|U~=s0bW$l|YbOCkItaS?^}a$O8$(u!SrlNM53lwcvS z2@@FO8I)8PT#R%+=czlD%+u6}V$zFE{C0<7W}a*?V^MT>!n38awJ?Wwok&Dt2@V-P z*l%}_!?t54Mmf8+$u!jZlkk#8L=BYAP>l9TF%FzfzjxO66#K?>^9D(%R#(C!>hkL* z$jur2FoX~val!RzlC6KA<@y{9jY$7ATvl{wA`P>aob+=h!262nZ>`e_FAG2J9{J_c z(1W?9A8ui#q<46y%ux`Z6jM{R?5QZ0MXxeiAG~pD$FU(!Im~tqr%*bg-o=+5NT$H@ zHlFOYJ0?q;GgEv@VOWL&RFcbtaRALcIC_k+ok-KJ-LyPzNdX_UW{Zl@;;3IYsPdcv z@=~%=`gl6RO1)OA&XmjdI&sM}cbe;sO0O_&M}i&3F@B9rJvrwW{S-nXztv}BH!Q{~ z7xD}KbhX+fx(k`Mm^KA7-_-J$T^X7hES|rL-nDn{%$f*SOMH+?MKrhC#7Bm2U{c&s zbgC=rmp!Q7l)=&7`6*DKiR*EdKsgQ#KKwe~t47un2=h{X5RQ9z<;MCg@|-@(o*La= zy=lB0uShXE#8tfAWSSB2O-mG_;q~{^s$i(8u=Iqc;5|Qx*>73cm3h_;crAs@U5lD}>ojS?l)IWA zne$G3*(#aKvey_`^anC~Y~k3@xN4S^nGI32D05fLcWL$y9lx%oqeLq%@iJXv^I!6! zC=_9an~ZkMlTpNm@%F+@`t#+@$rWRhhi5NJRYG! z#OM88$zLAqYZ3z;s37fV^ekalUsd(golJs#YpD+d!ei(a#%1cf?S#?%@l9FUN}5eV z)o#eP?ClB_XHP-J_a(5M+sPdHW9?LZ8~7)fI7gX92HPr$Tk{GQ&JU_>y9vL#>$J%r z*YR~cD8GK;4Y%l}MoaL%p*yvH4&zVQCC|(${#~qzGi8RAsfWtuM|yG+BQMm{iW7Cu z$_9qBStu8lmszG=(A2HSg@0v7FE7_giR~J}sVSGM>VoPrTi8~Kpt*9CRf0S0=EFFO z3iZSEWbvVg5kD0sc9CY||8;tSnHUM5f2(K&syVQl*mFBjOP+NUMhl81`M4@ool}AZ znB$Q;u(r3Tm>>oo4aeGpxK^YTjT60*T zC<|DGMoEucRQ`%tl>ra|l0-{6pD3=_6!_F__{=x-)Pfodl-#JEpA>Nn1&q|%QNR7j zLA=HMwg+99618U zqW2NRi5#`l%R^;1662HkNA2R2LJR{p6>$@tYsLEyrVbHC>6eXQN~@KW@N{`8J>f$S z!?Ky!6xUYtXsoZ%Qm!%#m*fg9xKr_U0K6xmIk=zevG6yhna-<2YW4}TQ-ZQ%q0F4oc&0qeXnrS52z7Pc+Hbu=!B_N^<6a~#H;)V*m~ z)Oix!R9;%85jH;a?~L}MGc5`I0D}bPKCsA>nL^8iwSm+otv)T3j=%ry9+$-_8#Y0Q zYt;Q`c3IX*cbH`)19FphJhRwAyoCKgFOj>d`hHjL*lhN(!eYekRl0k~ zuQCucg_vzmgx9nw3%0~Cs}euzV;B=B!7`z`L~+@sxu)4**o%yc!-i$ObxdhRh#E6h zW}s8;w^eU)lSB2m4Bk;MCqdlOx(B&7oAk>fJ|iRsWn90^X;f!aWAnyGKhmH&Wb`#P zjkojc7%4+JckwLhFH6Rf4Nb7TkNo7u7ClMaJ60N1RetYwL8lOP{Iaq<%Jk*1$w^(L z`H0}^Qg&8inij-Z{rXi1b9(p2mVvzps1(`thD!@;JI66V-5*+49i|oX6GJ=sQWxS^I5Md^&ktg)ca9P(6t(*N&teCS0-&bh zw(7O{CkL9_Sn_JPN*``UPF7f}q6$l77U8*eY1#Y@CCuM?PSj*-1{BBnqls$9c2NTn z=~n@0(rzu%($4L;wP5S2&yqESv42}|jCD?Y_%3-YRM{&G*+SIjjs@$n#k2|^={K+S z2>vW+SLk&}RJdcE6iSxXFlp25nuU;msRrunry%w>qn@88nJ6P}T)`F+>%S+oa!#%i z6oaO-cs;GU8Q=~J(L{oUOB3}(yAl`xsZhan!A{;68@UmDT*k$4Q&U`;y)CK%$40S` zNqcfs5{*lD*y2|8Y{wVyG1Dg*x2OV|S%>t`+>w$S*&L`leMZR$T&Ut^J?AK{Ib{`t zowY#E#WXvpke>K3YDa<>7+Q?w@GY%rUZ7ZvbR>!&t3}W(Yj73m;`6;H&p{~!4=$gS zS@^H$0IB46hU@3{1l*az{WI?kH>_`m6gUUjPeDxd(&G|0iENB@!-C=W;nBSj1@JkE zLsC#9zDWeg2$$!@2RtWql`ZTK{E8N5xPN2WrF)mJbTYGhmU{`G94;bHzA)uh3TdAM zB9Z$_QAcf(MOu_L&k{UWvvLWy??g(iccGSbMIr}E_u3puwFsKUz)qTGMs4E=k8$_x z=YW1feQJJiAnAi#;>lzNL!$n^j=5fj5qy@h6r zjE;R7$h+k1ST|n~2{-;kh8!9M89coO7h8_EU!uFQhodbj1lLu3W(=?Ui-%xSsQPUZ zg{heSxw>)CM~!S#Ov|+$lXNf3o!MM!dhR0Ze>>j~rX^k~*Ulu&cJ8i>V7X`b1=`N?znQune{EgZwONc4P?*Pxs{LG+3#>g(+Iq$oS0-7Rru>h9&*{^ zoOgVVv;&f>5)RjLzpgdi(^O%4Q*$2CKco?tcH8v_reYLKG`^fAvKj6xrg3Dekz}ho ztRTmZ9@-}jM^NuSJv1j&r!-&zHt^!(ft09+tSO&e1pHd=t>W}IrWrrG?R+dt(e@Lx zvWNY>8F3y8y|@bzd6Pa)zPMHh)ywJWPOM4&F8v~wcMo3&AnAL4LC*ddHNa`Jm?VtJ z=+JdSNY=(od9yLK?Y0TaMSHC*5MZ!5)`K5WG-7Bkg2_|CavCPHy(QjU`Cjavy2udM zEWu=6!t-=apw%E36@HB^FfdR>`yvNHvE08AM~0dAHi0A&ebLMApsUKnxKe-N^=|ASD3;~#|LLjNEX=J*F8 zGy6XX#r~%VIk^5o$jOC?`3+xfAL7p6AM_-ezobHk&0OZ*MdtJepg)H0;Q*7nYYm1HK+>E70{ zV7I9rfA}Y9mt7zS?mNZoWX+z3vCa#DKlFA(2Wr7x3cn5W*{pCE81YcECpR_OVD8y) z+G8}C!1m5{$4ty7vF>0)p3JM*mT7eQKNk_lr>ltu!sHTB>ghyBme5N)pVXMrtU4 zPRuJZ7oL0gKEi=L*A%q*ZD0iETG5ZOO8eG+55ZJXif^EnkPkEhrR^f*T=v+L5{fw8 zc-}Y2TE^eSCLiA*n8(w*nW5_@Foq?`04(4!-vPdQ@3#;Ry%rFd({fV~?4tP5z}-~Z z_)M*@{oU?<<6R`kb-;!^O+GtHK!>pg62oAPY5eC$ri+Q(ba)NL_JMi;e*BFT?jvl( zQsBK4E*hDxsy?wI&7Aoa&VHi{i%=-O#7&J?7H|sN7{oR4{-D_}p;Xme#Lf8rndho` z79~TWL3b#O7>swU)woaC{*eIbe!XuDhm0-SMPbBHnXpia(e78`d37WUKp5fH2E#yr zKse0-X%~f9CdrV$nW~ z9p?^B9y=oR`E!p$!@{bs7({UHD_SGO8Z`n}7@0H>bgdCgO~uk#8T=HY0Uh#IKbfhr zFYQ;lWvP#pgQ>0t9-!NF`E1qoE2~ockE-Kgh^D4G`dcYM7uAPPM?XUw&Y4rBu~9pT zwTB;TS^(#Xw7+tL(v^0nO-1oG9+Vxs1ic=J@xDKk{P(OI-FD=DluvxduSR#|mZ*;H z#2~=F_466dCY!EO5ppt2yB0~vCpSp4YvnBlIM+IMd(kdC$o0+MajtwSRh#=ZDTh^V z96B~Q6TJXT9t56rn2f^Kim{Z>{ZzHO!3)8$=biBkb}bJrtY@-LyO?(FoeQdZ3K0#g z5s^Q9w*8R=GYGvC7R;5r#*J7nK1<9UpPgt9| zf>DWwf#p?iR3-;%<8LimKLhXtn%;*SXseh=v*$$eVCA|Jo}OYCE&6?!S}5L554CNz zeLP13L1w8DQtGF@dg5<>U27_ekw^|bV|dN#@?svDc3h;K{*j!@sblyZHK$Gk`!Ts# zdE6A7-Qe~QhYp_@hfr;5H>q}SMr~O~$l7KmJbT_sk(AN#3l%6No5fZMKA~B|X=$Vv z2VjkQWHZ~{WN=Ko2p0981bliGYLq2desZ#Ya?^#2set9vjLOHTYLI?^2n}nLMONze zLL^JM3C0#1Y`*d3e|spbLjX z7xxPh$PNB_4XO^^o4qj96Ts|L6rtZwBthxPVo!KgtdU9Wqp&Vc0rPVuRySoy|96=K z3MBRPtIMs;2o>V)x9?&N>gw{z`bMS_Q}FC&W9NPCRNR_cr5}t2R`g_MQkW>968#3F zX#cr{C%1p)BvZ~+e4p$L@jS-n0Q}+i@1ZsKvIX|BMkiSj*SHMFg2MEyZm-?LovdKh~hI@KMRL+&k*3{J=IOi&{i zner;%_Lb2B`80-o@0`xgn&sz`ZqvQi}c&mM(j2 zMQjGaAewx>4qU2-FWVqZd@d8K`L1t!N=A9q!nJUxeV4hKY8tXDIdIxTk2UZ!4213m zX#x?r^N}|0E>1q+-JuFMi#xVNZ-CFLloSnue4lxuhKqYDp(2vhdZq93HhL!+mZ7V) zpv0KNITgrlKTH*yyD*M9FX6v~<-Hh4b5JIKByH8T5`77VDxP{l^s#mIHZ0*#wVGCI z^Ne6ux9Fu3(bDok*vAQ6AoJa1%~*+aGh-jJ*#$EuAqqktT?d`xbg1&5XwD2TqgK8D z{j&z%zOduhGjVb_yMIZ3a0V{ew~1~(|;79-F>8)UyUL%A55jqxuei!zI4Vg za@kKx%9Bz~+)4Zsvck5nE)a~P%5sNJ|AD)21Z|g~zvH;^G!umIQ`wTaMHMzv-VD8P znA%92}QuW$X`Dtr>a@Gnht=tb?Pp>$nS} z{C-;I-O}O_Y4j-aMJ#39`4-fE?V6rk+~l;k4E0R`6f=vm<+#Rk?L)e(0(+C=w(`TGnnDot?LE4JJWZ5mW21a~v+x`$0rkBZ zoMFP2Yv=aQvk-T?e6L$aS~nU!ZLE=Svyf-h9S^`;0sYinkQJ48y09r;2DES&TB?LY zXl?QM4?*5ojN0@(J1WDV2p`ENIG$!Vp>F!Gy{L;>LfsAut;|pf-R5PkW0H1?aPp~q zD?0N(&n}64j&9m_paS%TJhj-+gCY<#*jd=rRCVaHbCUr-}pyRwcMyQt}Aw>(>Y2#W&qaNE`| z!BO_V|7ynhy7Rp6mgPM2Z;K!e{6Fa7e;W0l24-es;`rZsnB)J|!~ZL1!1+(g{-2cW z|Gm!ipJe4?=KTN4$0KiV58RcMlOETq_Zq*`FLl=`uQe+f;Z!=>DfPCJRN6-iq88f; z@dWMj#O2oIZI?Du(=j0sS^QDM!I(4vb7VM~KEn_*KKYP@@Sp@ls{O=o3oJvdRhBHy zL#albF`_rZDa@|!lbuRC*Qvo<0Q2s519j#3YR^fo_v{VtbqD-#kux%L0h#D;YvWY{ z$E)rhV4_C|VNPdbe)>rYH#(sY3Wr^Otc=XB{qW$QfL{}knJ6kO(Mg-LmwpJndBT(* z%guigr&IJQL@E1_M%&~>#(eJ^(RkoZv~mV7t`fFx+yXEI6#e9VJ8*63?7i`J27Nei)dqC|UChIt z((izM353{l(+_na^n?RR4G%o=1HF-U67WU$2G16bEx0duJ_6SU^lCVO_rm+)Ikv}b z0{i5NDir*H^b3GTjCqiD2kQ%AETHY5bUmfp$Frm0mOcWH#3#D4pitachp!?u>+}@UBC@;pi}eh{MWnCHm!)N_ z*(Wm(JvWGQrBFC6(jV6ne~h~z@=$5J%HE(CUTe4a^ZDqVHfvkmsBOK>(}hkvs`jhN zN89@Qv`uM7JR*9D<2zCSVH`dGtM&jSnaOO@R%m;8!}xrafHZe72+nk}F`YGZwauW% zX0z9q$D!wOpk!(_Pp?70p;tY=YtH<&b56$xvTJVB2Qs`j9LByI&IfkiY1_`a)3<#v zW(p6dRXd@Fh$DV^Fr1u%$6aQqmHd8t=ZEoC20d3Wgs_swUF13`W5 zil8Uj{UDrub)0~8_j|!w#=yeHl%Esqp8kI9H_{PN*Ho$f1QA_oFjuaR>BO?8?3*lr z{19-F;rv&CJ;Na;o*Scd&key%imM^R50(^ETw}KgGww!_fCL zBoe*W3V$;i|9#vywVOoJC-gcRk93d+nQe8OrWZcaxR`iQI0%x%*T+f0K~cxa!9l@8 zvt-ti&f>yVYTP4aPs@(^h!b^%;O*HkWMnUzf^+%CMc!jbIb*XfiD35|w<8RGmRG`0 ztXAKI8C$VrTS+w`$(kwONv^kG@UP%om@Y-=*OkmFO-t+aRmSFjckQ-?EdH}Uw&k@Y zN9KLj9gBuj!Eskldowvr2=y835?2uHO_gC6{CN}AC#I{;gC&}CPd7TT zHKnUD>dsXqD;rkUGd7d9GuAWqbQW|rbXIhBbdE?EH^{o!X{#m9XL@0?y7svoyE=Px zkLaG!J!Ct|_8A(F8$Ag29qz$xgF0t5_v$YXU&4K*2Ag#ke_n9JAH*LdV8vl2qQ#>n zWW;48ro=~-KFUp+eO!htMl6mjRxF-NPGM7O!SlN?98?nOKAp?EbzlcZsg z#4YK-i3g)wyPy{h7#~+--Lh-Nh>Mu?@^K86Gvz1f&P1&29JE)t6d&ZTB=K0WVpcso z$a;~Q{zYHM(<&ZUmZQ~Tn@*~z*(Wg5W_%)Zus&Z~rJ4TDs5(}!&Te)coGlH>nRzsl zYV$yE@__&E)2$rAX^nV#_8LpQf6IQ`I^;q;&J{Ah#rn#~X6Z1$pH`ohuKwiP(sDu1 zTgjW@%JOEPV+;~^V6LW#=!qQlIa(csf2Na@GGQf~9^reLUgyy{nM>X)ExH##Z~i)& z@B5J13Zdz(8}e8bsAo2Cf4P9%{fNw%%FeaLd!1!z`jZy_^!z*w%YN8e{c#Zcf&4kwfYkZ|>NjL~S0{oo|c9e3+xHTPKT;9G>b6P7yw-tUz9hMhc z4s0_(emBu~o)}=5Y(B$i302mh<=~e)VjAY-4!vhSzJv+7XUlrt>QDSP@?$B%fI_O1 z7NCnobvPBmESJ$LTZcC=oO>|#Oxwi{Ot9;&-0PtGD>Dn?7zX1A_GTZZ;XAwe5smNV zd8EhLm+YRs2-V@5_T1Qu@{FcrJXm2Nu&lAZSQEWM!@04r!LO&7TUcas@JUf;{ zTB;)%d6a%p1=u<*_Of!J<-~I`?(}K1Y5IS*K%}PA%y1%wGDnXn2LyQe6zyFpPZ`LP zT>AE)3@}jw5$RwFVF-#RE}`XQ<6&_;fZA__E^H3YP3-3|P$GUG=1uO6V9L$k`LW8s z_rh&%cSa1KgyP8mI}mk%t4@x=Ve8Jn!^h3$fIwe+^!4^$FshV3e3dfVV-V~UEI2*{}$Oz|B+$_7U;cp;~o*5>S>b)i|$JV9%>hhi( z_cFC41kgk|C!!P8tn(oN9Q$1Df-9v#*1(LCB{gG`IV6GDhQh3R)FRcFO|lKo7c6ZT z@w?gf_WFRN{gdx4X#1_X`4bKAoA_nN)j-Ka$oWFVU>}{I-}zba_Als&w_yrsfCl8S z9@=|t71_{mMl7I&o3D&5IW>hHJEjD{JBu|nYC_pZ*0nh*BB$gye_X+io-u`65=KlX zF1F{3F2N?_%+Oa&%B^GOMW zx2UV8wSn4yC~~|bg}KxG5yylc5F>-5`hbYl_h%d{2pLSE z;pGYrG>sWmuj6Fx)QV=wuFQ(Wlrqa6U!^J8(h?LjhSoDK6sB7*Ibe-(45(1-?FfA2 z3_jQgnm@Zq1YCj9?{|)VmxnB$Yb|w&zhaqKPM3?dAanrvW4b!<=tUFhMobwo+_1;> zt01e^tYC6Woj{4Kx&bG#q(k{-BcO{J`#$E>jF}Y$JAP=5EyiV2zw7Jt^y}K?cl&88 zj$8@{nORDv9V+~w?yaxn+&ZI?cy=aR1ftEYY8}};p8ej4ztL+gk{ANGr!W|t3@EZc zSr6=Vf4|(t3&Q~hzQ3BQ+NzVM=o^03LSdlm^h;xIWN2l>YxUdgIdTJYdvGsCG};Oi zP1rS{wVo1!A4(BNYSQixWO|~LOdN@}EU)+ab|v~T)HH>crKE1GTv5CF7k06;v`f0% zAKgN}lhI(vPq}52w}#W4F#9}~`vBXIqCL-+iQ{`~uh%Gi*}l#}+yvD49KB<(g*hL7 z!|v*&*5PUMKfO`X`{_lE_l4-;reX<7j+?U0nAEzBQ|~ov$BGlOQfkR!(~g&i`PAB3OGQPvOWptaX~osQRQa9MxFWsemMnoLoe%72B?S z=66PFt%GSSPOi!Oq9G&nVrcNj{Xj_o=yvG)z6B0J@4@AsTXqjX?@wxPj%7_65kJ{g z@DJwhUxN7APH%MGsY=9SDY)DY4y z)a|XM+Z4FXtDU2KY6FHy(5T!nICpZlEOi{csM7wJp13qPgL)U9ymuVb+ymbJ9M0YB zu71sYjmaOQ*?uH72z<5HRUJNwEE!BwjiL1oy<>nHz5V!jGk+F;PUWSg8h#zmIOhrQ zx4+Ds$nOniRCrjNdu9&Z>HWst88Z@9%%Op-7Yq5umBd!UFa;wd$1FU7SprR}p6Ce=?aoT|aVQJgo} zd?sL9&)X~?DJvw!Wl&9*$}}?}9oP+Ooid0yX*#}G?2pmgCa#}*{Dyurl8Lzc>fEEB z$gsNCm^1k2sISB0OWLi%&Us|y)=AzQbj)D5D}bp6gCFQ;T=-|A1w|eV0^XjWdB1WAK+R(axt70tCuqiVZcRMh003-rn4No3To<&Y}WKQ6E*aLyE@Vmp; zHlWl-0xrk~LWq6xTNJ7h3+(Za3K|GqXuo_)n4l@8#rSVD#Fg=r+!O|0nx9UH&FU=u z*QXCQ0cVbfxkugZR@v*GwU<>BjI3WDu{qYg9_KoJZyw8w_e9i74Fq}yo?q4sWPa|Y zU6`hqfCxdn;ot8jtil^w9i&GmXF&O>&(3T=@jol#JcN9_Gw7?J8_-NWX zQ|`W2Z;+R-zh-V6D>Xq^*a9DAWv;YB$k&2e>4f8!LawwToz7KU#Z*f#DXg?&$whbm z7vW{X&d!XBUO~Yb344F1J9sT@=fR90DN6KTrE&`;w-S4qj^PxnFg^%CO)7j)&R?CU z$GgADLZK-ADxjhwe=kbJgo{k*xXaiJ!GxN74=wmWL4fDjej3ZZ>+L`+*DF-6cK9 zObI3|#EgFjU91-H(u7l}Ju+r|lv!9ej46O#UQ$*KYAG%JR@8;z9GRe`L|hUy3Yef8 z9V!%PrW6PAPydA&~Dw(whMk6;p4PH(PJMik_L60yv4Y3kR>8l!uyf!-$kXw0(YED+l)?{z9 zkJ;X5T`(JOzm_{7~0WYvc8)o@$@KQ}EMA_{{EI8pu=%-8@NQ%RaO zS>rkIWIATnbFlJZVia}+u>7^c5(_R!Uqn>XetC24hOrM5vD~{+fwoxr&JqXVA>kcvNHKdVN5(cMvekghY!H>D0G;Yg4Q5&7uyw6Q6-IE518lLAl@ zW=_IyidHwWkwXv|!|x1K2Lk#r*fWM;VvC+c~e|fhDMt<6vpq&i8>G=}{HI-HK1p!VC9nXmN_xvC#`k zi^A@sSy+PwyGfx)z9WaesTARikrus){e9fVq;+5t(IY5lWR(k^J%$nN^AvC&-Cm!& zAbE}dnocA_0{vW<@4U`dgmV5W~`gLK=JPM>hkGdJ^`qxsq5tmO;-P5nQw*U z-|p)2>hu|sZz!7jBjM==q|&x_gMaJVa&_g181dx|`Q8(Zzqf#3^U?Xv4Pl6;PzRX| zByPL&y&qUR%g0Y4doNU`@(AC)$=7ooXh)GU4@-?05mSs_42EB5PLRXfKDNC?a(#Ud z{|>=>tuHOJaCZ6dtQ_h1-hfl**u z$zA0z51o_CKNrw7MuqU~z0qj_>TrpD+x&(}W{4>H$mqD)?HioS^CAp6PnHT4e0f(- zCJ4;&xim^@a{dz7nH)dIvnLbP*k?U|h`J4`7pxi*2h0#5a|O*(9_J0LVAaj9rf)^E z;ojs9gqBl7y>{*R0yHE^fNFvdG*UoWg$CbN{pTD#C_LCz zXk6)KS-h0Q)v8d`RW}WFR6zNqd9&qa6W6kn*|;S!pA(WqAXAiLAxxI zG}1XELY~NG@^~4q*Hb2qN^cORhmhEgN{Min=t8mbukwK;n(pd3G}mr?V1$+RHziN&ueX0y_s zy1Q&Wz4)AML>-z55tflZ$wpPWwp3H|j+`QiW||bP;SFi!Ck1V=pRHD#bG%!40U#{K zJ-{+sEcxOnpeV+M*eH4!>(E0cV(& znP!WS6}`6D-m$FUOF}y~d;{x-XmvGlY9^@iNu;cKpH;=3>5lwsW>8q-#8+FrdHNMo zq1A`hv;GW0-UzzmJn!H$U0XKm8 zj7krEga3jWYWHzKbl!}N1*&19vUjNRd^!ksbn3r-EiKnvHu{rsH*%du;#hbiz zQ$NTOb^kHX>N*CVRL`H;{KrVWKM4o6(wC3b>*k|cTj46EIVy)lMvhpd ztzw2(d>xr1m+}7^U3e%F_$;_~-yVs46y)L>n&{0_2=j3Ok$mh`;dyOl=xy1A#PMjd zUWcY!VjX8g_dZv_bCRr^L-# z1n2hL%5COEs25Fo`7%z88HdjnHBu(N=li>^xKwnmML|z^?OOxA-Y7|I_jg6#72We- zDK~GYB{zwrEYC0&W>d|v|1J;rUD)Zly@u=*3MJB2 zFtU|ifOdLIM|B~~lRh)WR`%Uk_vy6axKJZ~s8lb#QloF7PL0Av{qdbhfz0^kbBL7n zCwP2Kx83R&7~t6F$%zrMUyOfd{@Q|rWY96QbEA zgQEUa&VOXKR$^Ts3YFro20H>`_q3iGv|jo2p?c9uW_tzDcVnUc(4zIiOvzgJVvH1q zjNa8(yYHdGPpv=HUlHh$npnJ(8&(RsZu*N5s$qQP0^7>sf38G^D_eMX=998@6zFRk zl;eId(Vf%lT&5mhrDkdMbtXH}Qjrpn7|Mfnb&1`%qE9A3N+5l$J}X|aVjr+_CQXMaqfR#YjU=y54r}A$s-Phs+!RCn)Qw?sL7h2M!LoX< zd@dtUg??();5y&Eg3$6Df@$>8(>MuYJ+?9#a?Vk?zpNelLTiw{%RS`H?~8fOO>PpP=GRgU6EA4sB_{PV1@3Yv(%u(!b-^hKDJcp}~6*Q_o0)&NgLDY;qa;?;Yv;PzWbk^1L}BiFg+n34qgM zD2{!n-K_-r_F#g1<0<(IEi2RuE;%f`sXni zz!<+-;u!Sbb6Vq2E-_%^dgM;G{n3L$8Mv7ENC@4M2())YB4~rRP*`qvB50<4vd_S0 zy(Xp%^*ft_KDS3z#KE9igN6ZcrU^U>N#8(s2#NZbXSRfVf`66-J0B+S<{c#hTqaE8 zWx08nL*n2T_Ye54T7o3VuWE5xis|w$-TEjmQzJLoh}#WFugP{=nuHxMHdEyuO-#ct94Q2E#&Fq|vzE!rCdL|A8tQ_B^?_Pp}Hm(}9 z%#7>=v`ie#1nl&z1Pt^nOj>lm9Q7>C3N54=n+JoKB4I5L;|IdOi2P0(2>G<6<6U29%Iz01{n=|wwCsCE9Qe{ zQj32qNlQPpG#ZO*f8=1LxSEtd(!;q_`ReQ#)5KFQiAqVJbp5fxmFTr(iblR~xCqYE z9nmO>jL&{K%?Y9AuHGN8xE|bmKHZxSY;NIt0_9l_gH}$`6heRGZn$i@APiGDQxB<4 zJ#@l&v2e}Cy=ESaD<~1@J5~qnY+%z3LLjC4^T$y4p-Y|0bbqyUYB59^Q$1*y)o44R zS#T2}JGQAG$xX~tU^296*lpi4NY;BDEqu~O+0UrCA=r_`nDYhC zPhbegG^~H)V+;)cJp2FYPyeanR+df1&yhgz*FgD}k}KLMS)2Wp-{aex|5o#_uJ_-w zgE0J0=|TQOq0T_S%)r3=%K8 z6o-&jU>0ii1LK<78$?oku7K7InT=X19O+M`{8B^sqion8GkJ}Qw8e&aB9Y&(L$e*P zs%uKCi{=_-PPE2bElN+GnmmH+TV_ zc>ySI@nx zGgLqY!%`Jq@j2`^qwaL+cb|-tFKK&TT9l+y0S!M` zu)@gQ396y0FKsL{N&V5^_6g@}IS!cB)U_IU$=T?-bhUDGOPc#l8LQ|v0KUlasigox z*GZ6yB$~rHZE28AExYpOy0bIJR?Bsobap5NRS#3x!^5hM>-WnZsRKtu0v2SgSX3(v z3GUEFCOk!xl?Ti30bYxyqnl7V{IKOgWGxY3l#54H^H9x2ipvU(k=<-!9S7u@^684> z)7R#N<6nMn{tP6BpA1^Bux#SILCar|^#bd?hlrN>5T58U-6P8FNotqIm9paDBaux~mvXnN5%P#63e7UlmlEhM0)M zerJI^E|LPu74O}dX z`{Q~J-@0Wl5T~zEU1*G95Ujg6Fchp{QdxmIP1xj2*`5h1F0alkl2r0{d0aSrW-4qJ z8FX+*W##JS;LQAo7<|K2XeRDtV-}vdS_>~@O;wYFg@aCj)k$XyI$Say?lG5V^ObaV zuLQ?pVkE;Ez$#VfZe1)pJ4f6I4Z#*p- z<{~xG848o=bm>HG7);DZH(AGpv*HTvk$~ zn#t|fC#+A6t%;7EmV%H{$M$Us{G(SLO^D%90$S58wvIRNow8F)Za?d_StPGURg;o3 zgq9`zec6H|@FQ84lX3ETx~3o4m|YFRl1~jYuGe{!`URN95?TDf_hMp;fKXW0&ye7F1MJK^;2x8czVj$#oN+6knl- zCewVEm&;J5K`b#e{QNn_{d^pq!Nh}8Lr_s%?9T9d#|SMhZB%fPKhj?Ahr&q4=wVyJ zk;Q|7e(_W-R;V03z4K}W#-b5|W}XBy(px2wMCHul^G_L>G_1>!b}ger&ld7uUp&yz zrqL$6N1~rE8dJO${GN}nwDy!uevb}pV09u0mz}CyM|Ew16_Cxk=d7cb->S}T| zk8M@i>}NVbZN;4;?H^73Wu=-daA+0D7*sM@PfpJr$4lZ&z}0qni`y?`)_rCsD5~0i zVfscgIJcMjQB8Qu2x6K0v}u95j}Fw_0oNsF1?6zcavD4q{Uy{so8ri zUzr>Sse?>ULaoZ7%Ni3C%ZBWsSz|lqT9dC@ z9@!H>*Z6K_vYYUkU|m~rgVn_ZlQxUj7lc0#tKE{l5O0LOPwYO>c!g;f;@e|Q_O`ST zYx;B1nP`Ef$8ZJpq<7_B0)U%d1F6cGFPbASof>L}QWcdni45Rm6=hN_ZgaT`4ydK< z)&Fi-mVu_44AFK~9{`mFy((+QzzT)yK!m;Iia?Yb0D&4IMO7FkOI8~1K~Ph!0c#nT zw?nJnmQe(?(Bs*t+V%W77xNo>8~Yv_6}=B|KXr%dUZ-D6-i~+NVM~GG)FMqu6GkXa z(S;-pO56Z)b7g+tQrAVUv+a2^h2-Xq$RNzjMsnAKc;vc-jR6soYq^)#hJ6ziGU`#Z zH*E8#rRHvC6xn7z)(+8>vfT7}W83+0)x{ZgpFB-e=kuSA*&E1U*}0kB!?NeK4tP)! zUd-g@VT^1D$^I9Hh`~K}yt`oJSqglaS29u`e;MIt+_uL%u7YZmJFu6Y0y_4cqc`$* zdG;S1Kw-l3bIa^JJQo=7$6j(>Z zLxmWk$VGvxD-N&$tRH;6deSK zZU8Z~;hs!bb#>y6@@}scj;o8#FN7zvJ4|jsDw*noTLyhQkQ3DU)d;!kDZ2=lN5?n$ zdLS2f7fZhepiXX!&odpmRPV__ua8lIL)8>%dh^g>Eo_Ej^4kkyW+E*r7dM`X-UWwJNb&)W1-D6G%I)p(Umr$MYu1;2gl;ut{Ih(X=nnV*`IJ#p{@rZ+AF-B@>u_ZJZ4tpC$F+-;hUyYJge0{rE6Gt$Ye}cK6KlwqvKdc(i)&@O&z|&`s02X$n5)>H^h| zYTW^8NaI*_=p>qtrH&oAxkfVwBV^UeFcok;Q6*KU(SKMnM9mGd6F#@??tq*gU3+tP zXnlbWqic)^DniKY=$&1>$lC-QxWBr%O80bE`;f%f^QJG*&zy`S5{X5&MrB*kA`l}c zM|k^(3W)x7OFg6Z;4jW|E4`nkSQQI8`kvs%y7Zp_a_qSOZa;Dl%V4~UWjcg;iGASO z2eykNz;BT@$yB9_m8hIkGno|HgkBoasQEls6YXcXB?LP7%(;TgNmmS05Be==( z1)6$C-k-tO_a1jwjCz}f|D|RBDLgw+$rh>-VY6NAB)E}zXO$l!_|Yr<0Oq|FhfCXf z{08=5Rf7BPoR0PX4FUhXm;HO_WBpI)V`ln>K2|mYCUy=2MmBZ=78ch3d}aNn(7$Xp z#_u-&QU1&RTYDxZg75h#)Ia(#vHZO)`*;0cZU5@S_IM~`EXEi((sAZ4B zs}ArFce=GLUk#60+z3`(4woO7A3xR%7qvYqzFzsfzlPL3^vm1WB4|v(i71xmXQm%U zXTY`jAv%H)oLQ}+DADm~fAhb=U)OcDSQreQ`Lw+>LBwK2v^W@e=r|~ilywP(hOE7> zsrSO>c2SsO35qlc43(oDtCl(cw)OdrI9KP?*N|yG()NFIu;p9Fvod$B`g}Bk(E6CN z?P|!^vshXa1PPtcgnAM;5fXbojo#9Nd!mIXGoQx}-ytem1O7a?CL?R<4CqFmK#8_8be6TMK zKR!H0*ZimY_%yZ7c#1MB{PXKMgmgZD-4Uq+YAJnM-A{dn%#oTC<^p~O;LInBZ5G;n z6ZLqRZRS@7@E*JSjweB1t^$8CM3xuCUi!`_y}98OUEI>j1A<%Tnm@ZdXayDP9zEx; z!y9fltv9_oZIPuMlWBu`+V&{8?q>6QIL&b1SH^oBcl0g)sO_d1)_U*7xlZLBs{m|eb5M?K;8U@B?~H)5Up!`m7W{&6e4aLvpzpsUY4HcssW7TtHA-z0gNxi|91*{!=3BIF1C~}4aG>t_}>0K|d z4zd@ECLuJP%ZBq9L;rwPc#V!oB>!2w{?)rGpf^e|!VGttdUEBn(D!5llB7~02R4nP--b^>EwZ2SPQMT6r9K|tg)-P`34Q>B|elX$us_Xr_c?vw7MeF^G2 z;n2L3;lQw6r5$+$unxJ6|0VLYR}XXk2&t~&l?y>n+nV{Q3l6h{s5Mv|u(UxVsV?=; z1iB3DAKXui)!dG#qkKM{vR*GnFYWKO`O9*e2pPo0m}41|hT3R`(dUU?_JW;!q5kZ{ zpub|^p$fBd*p8veTy@Q&;FPO-F&Fn9TwijEohPQ`b_impt=qHZoRm-idiz$0nZN$K(9=M^N11*ud9jpL3*5a;`>0q+k zY^@DHIS>$egP{-Zf}-@FRRAQ@DC50RKx)1ByBvcV+&n#Ib&=S}0)|wd1w@`DzEEf#6&*DEpYkzxYNe$CYR4$wtTv#M*HIduc=Rza(`7Eb1;u}Nc*2L zsn#%u zuVStwdsF+Fys3jWB&mRyLM;4aE3=dmIOD^}i>BtclfF(a+N{GL&N+r z;fEPwxWGHGX@1Gjw>iM8yfko=xdubQk1r%`=H~ZJsNv-opGFRovmkTWtXMU zmX3&S!N}YKwK1$IWc5r`=htc$g*f!xx=Fz+BHy;e?m+iRBI+uI{>Za@LrEig>tMY| zVZ_~g=wVr*ToHFRcUE_PX6|;A!2iZvq={-R-U0##{SMQi0k>!^U!~ zRpY9~=SZx|8Yk`PC28VpDQQWIh4{MS&?5@Wo^KPQtWw+4>N4V;XXecZ31di}`glIV z)6{)B=usUeheg5*=*B}_%G<*lsQE5PPm1mK#eYv+pE+|F7%4d5sdVz1JUxv3Q>{RT)hu7sYUS=}$%>ns`ypm?gr@Yd_QmWLEpHy9t zRJFSV{R%nZO6wAASld=NuHzDUXe}_fB!ZSK?=?eq@Z=IRmw?AlCekpv8=(f`FxdR zI<5WA<3O4cC6r>unxWon9W!TOPN+a8e%v{Bo!G@UfnI%7?`G z+~PE_I2<0MyFNDXy>ArPW~RX&(9!Asn6L%T7c{bN96EJ(VUy;LZYxe6pNI{D2X!O` zb{wzGKPyC#MdOp|(SMvx&e3iZEbH}x5tu9yT+WR z<|yEz5dl{XFGYIZ5BGU(Nw45P-@nMr!`D1Te?_%4!Ms_oc}I^E?r~jNZ9VoA5Ez2! zRCM0$Gx6~~Fk?lp$)b|xo6>K)ge&uy+q_nZStUh%?o?kqi}kWf@Ky*`JJnkYu5Z4L zGw@ggF9LEe5QIR221pBa*&#>2a^Uc<5J5tKBH3!N3$Eb&z`^{%-nbMogc*-v@ExgU zkZQ1kgP#iq4pQGZJK*FMD^)#-Qcsye>K?0b%9cm@zS%ETTexM#ZOWu}17pY%zG9j* zhIh>l71z@;iR!NcE4MM7APdnj^0LKmCl67Bn3BrrmufgD$*76N#8)QvkfOnkD)io~ zULZa=-?1x+cA^(yY2M9J#=5wR^N_hSgAWe}$NMoi(1r#XHb%{M(bi$Lf1{lC=#0k| z8&k4iH}DSbJBNb8Khcv1P-~FPEkejq!pC9KHTGO>x-wRLB@?JQ?b77)5r1hzfGJW7c`)L(b_aIniZIioZ_$VsRMmqrxISK% znc!tBgcI#H&-IcQD??ihNbBC+k;EaJ7jx#4oL=CX9@G2%eHISt1BwkyJIA#`k--uiY=_j%p6^?7riTEqShxI7*yKl4X7DLI)3g!Hnh z=o}sQqf)9wr@ZO%Fat1JvKEk$srb2Yof#{w$FzJFigJR&M+8_o1JK}uOyyJJje<^ z+zDD2tc}s3pkby#Il?+h{axsm#IeXR*;1+R!a>z%G{~sXqG(-NP1EorF_|-oGr4ti zV=0eHb3iGUs#Cm#Q87$ukV>IJ(L#H#++m@)tUYqu=|M9z@Yy|gQ$clLFnKyT8n*0$vfYPgIVwTLI%Baq%&Z^EUynUc%0Mo(BZcDFKi*s)S z>e8b3N1D~FT`OcC-KwMBEnL#qD?+DP9p`nnHqUvw0wSG z4vtVuW%^dYM-8&J)VhEL-0^eb@nan`hw2)+JXURUgbw}2l28`?_+~YfNYQ*sNY*&K zc(GC87SGBUi_t`TD+gJ>b`;v0A2nJbi_5HeXlusab=3pa3(X7lN~`9XK&?L)_Swwv zF?1B)Ua!fccTQYi3EN%5SBLf|_BZoy74U7-FIg5%EAYvD-InZgFaNyj*e)x6SBLWxA5>k z?g;h?^%S(t%(OrAM06w#wH|5tTZB%;8@Z?$B;Fb*pp$Byd z7HJ|$*0D=2mTb(Qh_1y870lt=Efo`Z)K2XFoQ#8I)iH(={?jxW2~$H41DPuNXKR{9 z(^gOpDnSWqq9=wOMHg`9wkH-!ZK=DM8iG?E+AUk?=dZ7&sFsC`Xr84{-2d;&s zY*~C2;%C5iXK-ik{x{udM@?KspCVpf6S&S&tNV#W>KpiLu=UU`KAX;0`U5V<6W~6% z9jkqRo^2R4)=)6H#<9o5+E7|iq{Ki`@Tk=oN+Cz%;X{}i>jSx9%Om*>M-Avi+4dyY z7tbA&yD9Y9%!**~PlZ<@Hb}hR!s!INKvPsQ$tEF3F=7DRCj%hH*gcM7oWbuHoE~U4 z0G7ebnP3^vC?i1Bze0tE$vQ?7VmIu)U2z8Fa( zZsc%WvTzl5kr|rwH4N5lroPWC5bZ=d1csEDiN>&jCJn$?hymE#$srFmzR;)5^~NS! ztNnQeI2o&zld}~|46oPd`BK_cao6I8u^mUJj5n9JFiSSu6q?0xhf;LUZA@~Kwngm49Cw)sTQdok=wsh9ROtlg1|f|ooonBHtSozT9%vv{JtcT*RO$z;jT z;Gt&f)4L{5S-$}_G~TlL+@NpX3`AB)PNgFt{pO$IRm2^CXg+7-a8|Wp3@^eZ`QAaH z#3JNHltkm4HGgBf(F3qedZedtR!Wmlgsub1Y#%eY72^E{C*e*AbO;(rWkyP?eZ7#+ zJwq=$T{?3&8a6_CPX-K35#Pn!m$3xzE79CdIWZe| zY$9sR@~7c)8X8Ta5Znq$Dvhx;l;2*fQHW4dPY@5@lX$cx(K1mah_ezyfjJh{Y(q(O8}2K~Z7W znWV)*Ll#<#&gGLT>90H`{{>y9W!T!DSOT|ly!4?tD>W5JVTj*q9|4jE3vjB zvSrH%X0}mX(KIFK@N{k0%Dq*1$_J0%VkE+w4Z4v9S_HtwwvioNNkfRZL+D3*B5@Bi zU8SPoOird&nKc9FIF5E^?m~i^zUqX+)npyW`#yW4jln*S1-7*HJGShz4XVu8N@Z#% zs-I)mY=))sW*!=v?ula%TY-PDqh$&*H8u_vVumly-wP}Sz*d0))u<=NNx%&YQFcCFy+jX@*#{)5^k zB`P$9=89zHg9DsN0eRh6;Cza>ZLWhX;W)0crT`R$SP?BasM7+ejt6k5*UV3ol#4h< z$u_a`g@+Ak3xKQs8ZsA|sKi~{m=NU}kC~2UT^573z0I~-7Nbh2Qr~G<$=1y2=X4_7 zLHeE73#83Yo0P5Vj#%5G>3TdJH;ebe^qM{yUWdacE+57!AGXKJ6(aCO8f{>vk&tgf>ITw1B+Y2}yVV;>%t3eg zLe6ayGTOLfZ)0eWDd@JyX|;i+P?G~ZYeJTlUF1Tc-R|G z5D4w(Xj?GRK_o)gdCiZgbCEUN<5Y4b+RLdtCHG}bgsU@z(6}+?gpTERBNlcbHUsUZ zPs1F7QGnud4y+&nG;Xk!JIc^Xz2-uRxuWIqr{lEj{WHD1B-WxD*UFco_Qd$e`oX+& z%45nF*%eEh)HcqRk2cb)+(uZ)k}a!DrS4KR=h263sNQq3+&+)H z=-DJ)5lgi?^P9FEmOc%Rn=B~tXxCq2Jxg)dJ|JwptZ*R&)OoT<{t0j%g!?z{NFSPU z=b$jd89e)s%~phEuz597jcYkD^cw7CFp1sb(XjG>&MUP27*0PUz3CF(XF%c-j{W?U z>wX1hW+l43K2zRmbm9IUGTJh-dl`M}pgspbAIZ5jpd5jjK3qKrNLoEhhHo{m0ymY> zo6Z7ChP#j;Gpr8F0@-hHZZ`Wzg=WB{T|VJhS%*YFk&>sracLX%2wNQZQ(nscKNp zw4`QUzO+{5qI0Bnrj?E&N{DmVOJWEi^nl13LQ80o-l1jfQs2_I>8|4?$j)#MPrg8I zBl6LleMbHf3|KSOywJWdYl2(7VcI3I`D1GvqP39=ECaaG>XKKc%Ee+=*~dnnZ4Hj` zibYB=X>$Zu>B>vn=@WymvXXsV33ivDl0AUWP4Qyj3I`9Dd(aC1gY9|^&ss(!J?i|wOVP5kEHjr8r72x5+00Aejg`qn4^HuqzA(u4dVn6AOv1+9(Pu@Nf*Wm8o&vw zG6F{W19G1LShY*&_ulW`(cOJ1Y5Z+-Q=)3oPl@hclwZuk+K4}Wwqp(Na!9Z(S*;{w zK`rU3ke5~$UDM?1mh~-e?pI#9xn?q1oB9b1Yq8D+^S0SYUTU)MkfHFq77S!0CGS1r zigIyqwt)hbVdu(M8fhR<)S@!_aeSQR8Jc3K$)HE%75$QzM=vDe7Izxf)oamwYZu)! ztr|KeHIh}2swB(@Dm1BAC>m2VXlNHB8>>4w%&1!dx4Jj@t?BR8nwIq+Q*a#m*EM+3 zJ37KTbl+o_4{XO7OQ) zUH)Wg@V!36HF&{KD*AXsd)siiaQy(Hv6M4uYTN}qg}(OS<6T%3y}5obgugC3=03MO z#A(7ps2#S6gz@XrZaZx5CnWw}xaIcwTrHcno7Mf(#4o;>1(}i}a-r694vBqmq=GV4 zS)QTQo@XR&bda%O#oq^f_HYW*9fNu*OLAEDe7k2at3oi9B-2clkm|y~d z7AQ~YOhc&eygDT-^v@|m!l(fkTtDPcAr1&4_N3SV$Hg+0PzUak5W9zIbD{g z>Eo`ZxWgG^YdH;EGv2VdGf_NGZLjnW6<_!L0&lQpl9W^`c5V=<4I9a2o4yZ2mkjIi<1TWP*9hZBj_nw*9%ugA`nYCR7l z>XuKa7cElsPCNTV!F+-yPj=F(>cFY(#hiey)khYBf2p>DG zACX-pZ$Ty)m0^;KFG{T==$wjiz-^g4x%4F;O3!8<6O?$@cPlDeuA?tqS2U+=NLn4$ zw2-pMsqUK8J}PloY*Ck-NHRW5!9D;J3#gkxb!PK8i(i&YXwlg`T|QkuKYdz1X`SZF?1JvX zw_nj!r`x1BodD1Jx^*)G1YPrw`ZC6F#w;fDzFpt*94XAzNJ}#fTkF?)2w7!GDfXIH!-Nit75Zz?cwbswjPw(i;vz# zeiQw=7|K7o+C#~G2-ouT(O4S*Mv1h%>XQ5b@!@~fy}A-L6G-L9a%NR^jfPwSCBNYh zHg3~j#vADZfxn^cUfL$YMk9B>t+lCi8)?4E3Zgz5SNr9oP3hrmav1&D7{xZFrpAH& zO0cO3(9r?zz88c1LE=i=y-Z+BIF1S9Ki4xt7@%vS#kgA{Xq0anPi{%W9zgrsFg*5J zPAFd(r~I7hH$5OL$`53_NHfPzj_G5KzIaxv7}`LFir;(Y#^hmh87L3hT(y0hv(`t& zkaI9|IZ^QJMO?7;DB>&v`vW5C?WCmz!vXlajPrN-5;i;Q(e_y$Vq1KzR*p}N#F~sx zx9B4kf@=eB1oJHRBE1yST|j+x4lk}&NB{z_;dr@Z{Sa< z@$IsGp8UY!EsAOIxqS}TkFV~rHelOnfi}-g2~rG^#!0AH)$LGzITPEkEi*=-fsfML zGNOndi3U&3`1U@xPXw_?nk+katlt(l$vel0^l{U51XKnGQ@o^$pAxdk zxQ^O~=)W*zCQsSF5*FTs!`_#c2%ML3TE0*lSs6BA`o7T)J)s8=^;Ad&CAc)|TP=%or(P`Z~jBVrDHdquEa08AyJV|c?h z{dIS=7X7+$EwHa=$XflmU#F@nFFX3{?ZNJgQI?w|7sgS;wp5J~FoH~*_ zP4Jmg?vD1PvZNUCcRm)HII6;CjYF zwFGagC~x%X+>Sho`3xlUMSYW-ektIwq8KmFdnLS)zPX!cK+N#eR6B4oo8*w<4iBL2 zj^?tPCz~idz~Ya!F3;Ea8Sf0QuML;2s?IU5k$MN)?13vR9i6nP}$c4^?H@qpuMApMWFBB&COM#4Lu%1mg6m) zX_>g20fl^-y16~&MwAJ}z!#0s0lHAo5}FhqrHC|c`}w6~LAkj|X*DFf-gy{6HLG9k zvhQdeeKt*-u4@--^}~<%Bbo4A$lBbuRpo;sZ^Ir18b@su z$0n+d7!{txeMADR#Up|@u%zba9~#5FmEyg@IF0WMf&DUJmN zzyev&eP*sB*$KeWm5=eilX^j_B89dhFog0V7(=Cx>7+n2HlD=+Y=Eum3|qVE_N4xz zquXTktjYGqKbpT!CQK*Af{n-s0|kLxo2ZYg#=^>s zIi-QC8w2~*yN}3W=wQT-12npwbI-xXY;QfhW2im#Ik)BhzL7Q|-4$*RUF5At$wCk`(WgU2Z^5kn}KMw<9*Dc&i{*o=CG2va0}Mv|ug6#YYVg-F9;K+~Yp zrILM#eT`X6-SkHzO+AVRx;pwQ+A8|!K@pTgrdh>{``E)`Xv+XnL%nMLqWhJx9TOM! zy7|W0M6QmXE*%wl7S$Yx=a^Z8DI42|-FmnO{=m><3A9X;eb~B~l~ul2vrYF^_pwIB z`IT~W%N1SMW8*pO1GeBT!oOZ4mm`XWX%^OP;r0yOaPP%m|Iu-+!)b2|ZZo|GW2J+z0f zHq_}(RK63v3+9zj7bAvl1&-?{?<&aC8%8v*qnxUEP5A6~S`gj<+Imn(3-G$lPr#OR z&+)2lm+K>d6>=E5(7OSfu%QT6gYX+nh2j&AxuIFPlPcq;7wkjmr2Ivlwa)?T8lOII zP2TfuT-wQ(N#e<`oj(q^cBPl{Pu@=kmrLAWQ%&6D?b0@dF4HFWunZMbLf^3lOGM}u zd;9|JYR_b<;h&V@_;eU`6Tu8zGcI7*_pFMjB~muX$I+)&c&otf8orMe?rQ+vUR9e# zu`hZZR>4@OkR4Vm8{yh>Ypjk9C^{0NXq3E5ey%47UUb9h+m{LVJROm8{w)GF4#TFG zb88^4HnVHo_4xB^K=s-4Yhe2<*$Zo;3C5oto2>aQXyr{6l{91A9aciLls65A2{B07 zXZ(W+Pv~N8udT$`8v3L4ML31kIXOSg&K1x^^m%G7ZH2`6OOGu_6~tH963sdPh?T-U z1-7w;2)W6dH8%}he+5L2=M^=sklAbIaUO z<-itw$*GMP$&oyR3`rcc^>CDs&bo!S%_RS|7w=aGCX&xxL~S;>^ci39)vBC0rW^$j zE?(Y7h;nIqY^{(tk*p9~@W<9gtRSQmUbHE&t*?4<@G^K(l^sPktxdo+1q>)44M?2k z53}PVrB;q@3W8OHUw7c3N5a;TxbJ;ldODm9XLwHpkiDS zaKE6qkc><{fz z{CFo1tskTX$Z^`sjCCP7jI-~|w>|~^tG1BRfxj`FinFLJinhLxboJ%{avo-)V%&G~=)LmC<5TDurz8cZ%+5{&qx5CQKLCwI5_1>aI|n-k z&yfu!GE4PV)mh5aXS%a8;j$%9j@aI&?3ANCuP+a{N?0PY1!Wor$a;3UfS$F7Z z+~{h<=pXyS0{e>E_Pko=oP>(fKR?P!<&>4EQK`$66%zz>L=JXQ%Ot3&k}1M<>C!&{~`bDm9h)5?I3R?^SW}I-JlX3MJBo2Gnqs zDvDC&Kgud96@Ms!u?qPcYx8Q`v6Lw_)W8G*atF%(EGnzesHtQ7{%V-Ulr=At5Fb-c zQlx{Ig;VhxUVy@m1J?wCEi8|cu2fU6)eovI$!jcXY%Mn=#g%BNE3jV>|C7IvSV-D{ zT1J&9VniT5l80)9WkWE!i%N=04J>XpG8#u}#IhGYt=G!FcbbEol%SNPlw1x$!J=do zPHhT&uPUe2*qjszvJpV0Oz(_d^{1S&&6&lqyZISOH>S|Y5)vT?jTCLeTB0QumJr^6?zTN-!_^J*CrkdF+`^x_n^KnUz-GLL*XY zUtL(EJqd&FEIJzLy;=;vtu|U3u7?Fn(fEL28q^U0Am~m&h8A8`k*{I01{kB!b_O%U zi}ro-yv?2g9EDhCdu>b|F!FTaVM({~<*+0hh22w%g|N;;Pu;4Db8*oE)C}?ov{~!> z>a!SF$+;A{37wt9bVrjef5P~O%}zsiY{Yu=pt_uup4vkmQzhSR;a;BjOQNpeSYM3= z)NC+kGe{F<%33=e=P^C73>*#`m`bh;hlcRmQjFfBoLHPSywk=u{`3aXpI>aROse$c zk=52_${UcabjjtNk0dfBHWy$J{!)REq5$WGmIKrjnKlnZgi;4F&@Tb^Zk5Ae$$>-h z-GrKl+`G$B@?YJNmwmvfz;i|qo}wRLf$0*WmlrIYHV1`rDnS=z?pX%Qsf~?P%#k{w z<}XC{cIinG&B6AwgBp+SZG}BwIdC*zrb3*D$q?N!e;Ym0SMEfWW%e!8Il@D53wpZNX{byC|I16+sO-@ob~{oxTTKwWGFi z$SCSqU2*vi%yq~r zG0j*HRtj)XCBbfa)_rq z)O;P~7sE9u?2+SuUFLMwk7wK=B=*Nu4DQoFS=M~oC*+|^6n$A~rebsrC1=WXhJh=`HYsokhv z3X9L2neWq(Y57r=%vs41xmL*_JoH0oqghxZg_rX)7j<`YdR*VQ_=lcr?{C7#^h!kC zY(?Y>`n<52xk1T(yEZ)1Jv4KDix7+<#LT&taW0DoHCTRzQKG(PShB%9J6KN+B*)(8 zluKBi_`yLhBTWNjgYJGesQ4CvCdEC~^(X_WxnQ&r?9Ra~xg-OWjYr&b2X60o;>J+F zeJvUrmSdy?soD9Zi9*g3?7gl4H=V#2d+t2BO#}D&Id^91QfVP%OI}2$n|BeFnfnE3 zMXcraW?{lX$_AAq5G%_-JH<4#jw%m97%Sc5nQCmEJ^PRQcdb;i!RBd_Ko)vzt+0Tq zBg0$we{^arYb?-~K|JA${%Lza1 z#I43nQb9rvQ^N%HPas$8Bvo^n$dUk$+C-KTe>TvACJT3IK%4wAt&uaOp3Lzb^I_zY zK)SqUkTR1xR;2l}lvz~}p16kI)4erEL=}j-qcx^_-y#LDIg6zsOMVBEyGpl7DsR-J zDhyBAPF70>W5s8cn2bT^=Pj{Dw*R-pc)L5E8@*%V6PGn#iaag{xkXS z;3-9>ZT1mU_L*}?Ma1H%vzjnC6}m3JE&RMVqWfjk!&e;kW9ybc4z$BZhB9?mHx*J(%ADYYh=d1Q!ZRZ2v{|M_aINwi3L zr{0!Nd2g6j7_(FWy5Do$TUP6(D97oWF(=c3oa>`%>?L}PFpoWT7+4-Yg;Z7>zZba> z<)Aa7PNa{V*OZH6Zx~r@LE_w{rqR1iWRR-R&9~r>Hlpv;FBj`G0F8I5snm!p3ig0S zrY19WVTg}ae^gg(kQ`EkoZB#@WQNaukCw<)%Mt$SaP^-Ytk5adaQR=9omF%k+hT1k z%VM&anHgKm%*<#pvn)o7nVBqRmMmswi9x;GZft%k z88L$K;LMt7So;Qn&1m1b&^tdzax!PCEh|+gSC@RNT);S)Zj^1%NWLT z@OC6%WT7m&;O#B>EUcA&MdghLyU+N^c9T0_OPh-_&ri^pfr{U0dP3 z-BI-I1^I9~(hRqyr!#&vY7<{qVR)48dRji{QZb|rWjB~ z+7SC`$`EZ!%;q{J@U=RI8;gi9MKTH{?t%visiP=POmMdq!m7uGd3dWL&W=4EM^hFr zY1rj@sC%Ul8bamzEZAskWq6k`mHW|G#+4zS`_m3ybu7e>*EfbMZ?x}t4}n|ju1YBXQ@57C&Rb`@6MYi_tFk4 z74TcXN_Kz6Cr^B#ziQ+hl2vy%4e>1VUEL;S!zW-%9gdP0U(AU+JFBhciCt|PCtFn) z|Ftv(2kN{9j*eL!{|=fzDez0uXw*bx(IM9AJd?;uRr~@4$zP(TBwvhljcRGu7?rgo ze^j#Nho=+v(WyFt)34Ylu>AIMqWaN%FNh5jLTiBz)Fi8RaU$ADXvD;ND{cCEZYfRY zOYC&!z{r!~0fLPTi5>O>6?4GgN`K(G`(~`YBPkhc4V(2EO4fhpRNj$~g_e)`G zV3z|EZa~U8*^Iv@U3C^V5yuR4Kn4;M97eh-f9)2r7O94#L?J+6NL!9+I#W;-P9oU+ zNHz{{cP4^FMdGXC0y1eoAqA8$M{iM=0VRA~t$#LEY>5CbN2YX5d_L^99L?8P0109- z8CuMj#K&(6*^+HcS50d_iXxkI=(^9y&Iv9Y5XmDPd8KfE>IO?1J;tCTa$VZ;@mpPv z6(Ui8ttR_w8PizY2g|m7#O191S!gfh}%bi0v%*6?CT~-xaEhz=l@AT zmZ&L+AaOIEz1|Ta>;2=D@75>Xuj(y1;`hhr3vJ5ozl$&ayC#W|g^`W*KSHzrTTzne ze-b4bJD8jNZDy8@l>=x$0@jKGL$B-vj7%&{|6OMG|LsKrPW*2&v;S3$#PqLXBo;RI z|4ED#KVF&6@KyAI8*Fr?AJx^0AeJb9bysvGm(Rim-`6*u2;d8;v3qu6%iEaPBJRY% z+wR|I>B;I-Gk)dKX!IH-cQ)S4?dZm9b-tV8g82b`&cuPq z^Yp4`p+?mpUE6u`fu;Bp`sG!IC)Kl6@pM#Xr<}~mfl1S|QT)O877m=_K7=)&i!fBB ziR61z=3seb!5i&s&gw5otLoKrcamLE+P*M**SOkoa7_jg`;|@JpQ@VAyR>S(Pa+vL z9mRD09(HjbGqryp>{3+^4;Pys>K(PjAle@4Rd(N^&$8XRV9EIew_`kWv132C@}#`O zX9d0I0*)@$yKY^Mg?y$sr|@|gr|~w`zr*T`~qAjhl-;8R32Jy#j}N z7O-zH>@dI=aKx?Hp)G*zc?T!(9c)7UQ16?bpii*2luvLP>pK4F=(L`l^ZYd(O#h$yroUb6e;eHe0Oel)@HH_IFf+0d02mkufGd!Im4)T67l4D6 z000yw{qZreFaYDXEDQtyjz3!#;CK!KW;TXD`=I~qX9ot&0j&SFpMwF|yvt6&&ISOA zq&a|MCMITJju$xL&mUOWfWk0F0%m65!GRHV4iZTGhnDT%Bxb~_RBS(h37=@JxfkhT4@PpJROO;?EOASbcLICs_oo9|2 zWsUiNWxy(%M-M@W_%W|&TmsX&R!ke|8>UiTUeLO%d7|Oc(6F}bymEJ2ydu)H^zpF9 z6&(}QRiq0;* z>wfflW%u#zIA{To`b6!ZVGuj=%-^aGa6r`ZgkBDUH7wmV*sQ%6@+q9d8Hw1^bit zoc8$%Qb!ID-vDx6K?7%o^@&f;|CacgQ>lOP%K23Pmv1oDK8B6|+{)CaR$Si1Tf@Tl zVcue85B|<=dd{jAU6p=Sra^v$DSNzKe4&$WT?F-I@J=cNzIR&A2*SzVIOn8JGWP(D zW@*)X28W(=Jnd1O5l!D;dHSbcpjg#cg003@euA0*4yB3ervg8E>S0uAR>5GlS?%fk z_5I4>ErC)mWjs3PyrzxN+tVP|1BNSlg>zsWzju#$V9{ZXp4avUee~{ZP3y775v`7B zu67O9GK!Xggjqf4d$=1%XuKGfG0!UE;V1bLQjzfR5p;Cg`|3jj*vZyMOLG>kk4c{} z6O~va!E`d-Zyukxa7*Y_iz>?1+eo+ESm0e>P7)KYSHj`6~?SM9{WE(V)}!~QWEE=^P{gFT>uz9 zH&whZ_i$I(!HDC;xsGgyG{WJCR1hWKg%PTXQ)yS^gCCcG=UCDZPxRR=$J>?S3m*J2 zM=bmzSs3ibysA*G$hm&qs^`XLvk~)nR@JsfXV@b%CnY`J4RW0@F_SCsf;f@|#Yy;( zDq8p}Xk?&aDO~C}PS#*8zoydLo;4?}KuKZbJg}Jr?$J1B=)d>xvywEd9e4?R7IeZ(0IIKMWdJ*rGrE*R4i-nO^1nu$ul*d*vYV(5?!#4;)+GB(SEug&eGt))I!DtKJvt08_2)dsP!Nx=4C=n} z)+6mlzD;t@#n#*mCgl{+_*3F?=hG+_!J<(|29Nb0PyFKA7v|@Lbnv%Y^C!!)JRauK zQD=&mM}zX+1(33lsS%aD*;AyTl5xo^BhZZ?zDY*rMS!{wZ<2fh;@ znTnZ(zIyEs>j%l^`wOeB4@OD*d>?1U)n`-hFO^5lU9;B6$||7Q?dNsYO*Wa2?|k9E z*6+9`5cwW{z(rRl_Q@3{H6^kBXo{R!dR>1UzA(!dl3MP#@L5*ZK;hIJu>zGtzrf?D zG^PgWn*r6g*YR9ZfrMzkKwA!-{bJxf7X^FPrY_^0cw%|UE{oa9KkCNzkr?0e zZC7)kk6SUPJ%=%WrTS{WA`;>)I*p5-u`GY1^Bir%y5;III-d`P#L)uoFbfX3JiWtv zz8tH|IDGknJ4Yr-@+G`A+19iyUk)HrhNhf_7hgtnI!V4L+XlE2a0bmlB!xUWHZNpS zPK%mi{5ny_a`1kmP3c&7{F|>swRD7*hx|?daC+H?vj}rD=7SkQ>+C@f!@%cZi4DA~ zL$;b8wpkwX0S*_OlJvX0{-v_9Y03V&y|;L8f+yR&o9o%RVj+p^1D*IqIC)@tDklCD z=@whnRK|I571cRtj6%{9&oyS6QoVCXQ|?izj2! z8;gfCo~Pe41rgDWS*tgawuW1hM`Bf{ZsOSZY7I{I(e@jHg4iau1;+) znh7#j$oQL?>}m;B12k#L5+$GE0wM{)1UqU~#8O85v5s($^rBoMnH{s|89M4pbN#VQ zQbq5E3fLf&!_Q;dR%`siImXyty|?Ak>yzFHZ<+BbNR~b=iO~eH-qZbO?G+h zk1&r~eVUO->>-zAxi~V(`)p{{l)KGyaeq?9)2g?~x_GX$0Zx1QwRg3Ew8D1hd7upE zVB)cB10DFw>mBhPG7AYPC19)z6(Bd!Y5e6aBr9wCwv39HZY|ReM{0RoV}zggQyS`v z(T*|5sEKpTw}_Z;tH0Irzxd;uO2X`g411O1$hV@5!44|yw@Xa9$KIzv-lmi_U&NMX=_p8wl@&8<`<0TG@A}9J@_~RvLTiRw23n>^^VV& zE(1|{R?a`%PioIKk$KR`MF}91eY1C8NQHCA~KC zd7OPWcKq5tS%&3}_%>s?w*o!y^#g7E=fiUHB+tG7E-rexX8PJE)so*4xBcj{mp|(X zcBp7#;A5|t!vnE#TOq6sHu%$P#iqRPX_y=n&G;H2X#)>*o$=DfvqaOco-o{RDsJLJ5JrI@Dhl^rXu zsOYKj6g-z47peO%Y_&f^y;3`)thqbr(T+HJ!BAgi|g&7BDL8zVz|C zR*!V~K$*f?d{4uKb-JqEMF}|GQ+rh?>*QQ~MH%O1h>aH0`GMgi^5(h7tP-ZVMl0&y zfgyre+-{)!MdwXHje-u^eH|I>zz+@wJmuDtd#qJZ$n%RGM39{x4$ghxvp_g@1X+T8 zRWZT2Lu+q0WDN3;CiHwzaRUnQPnMJ<%T!;5Ph_%M$tfq)ee)O|ZD3n6UQ5^EzxEjvd@&Pg>m&r>>p{Zj*iw90CBZW;!J0r8i^ zrq8%4EQfFq^ri&*mn6A_@)U}qgkys}?z~Bd*k9M|Yl#eTd=p6En|len#a=@I#dETY z4tIerVY8qd;l&^&B#?nSUxQNGBy*7@Onuu12ixfEO68R0L754Lb>d%Pg9+$!JsEIN zi@v8vBZvq`!=PXq<&j;0>j(*ZGtfM8^TwG~^5ZBXfD_D;Le4s3aw_UoQYh6>O7V;n? z`Q46^Dvqx~L6a#2kwL;Lj+97nJ+v0of2;WGPD6?2EYjLAoUW9lnv}l(p%VpQhFlPU zSOOISYHwh=n9L--iW*$Hr4tL8kWxlZ5C^y96T?l)psSYg&|*NK04p;9He0}~y@^aH zz^KmETxDjAP=&Ij&dyJj9u)Ouq#r^Y!p~g-NmSdWvkV`{UlTS^>1}6}e4a$*cYT*I z<0heKgT`YLU3$EWQv*9&`YGD_@n-9pPI|dXc)@JKzTSHxIuZ16=tfDz@(5j)~TBghN#NiruUbYN5fU}jN zjA+Ed{;Pf_nujB{w2aI=e3@femTe8EwXg{cB;aa|taWC2bwy+&uVHzrC& zC3D;2)PzQ1T;}YMLS_9XHR+tUZFwuxR-~X^Qx=UZT$Fzra-8HH(_5|JM+flKKegmT zLyD&dmVSbezN|{s6kTidYZZ>F8$Fj!tz9~8jUu^BtMv~hk;JyEpMdHfZ zuZu)n>kRA#LfuluVbPMtCHO5c))awOJ6bzRE4oe6n7Ey^LTp{&@G(16o|yhA-_8;e zT1_`kXvnmf#{GH-mrh4}SA3rOEV&+G$c8;~_n!I`B?o3eoZ9ahGTwygFnmff*pLB3 zb)r3m`qPLnwFuZ7l8sQ#yZXr3Fjyk@S7HVHYFJS(do!{&YLGI84VyiRC@QfzWrUEV zl6$d!^)Iqi8?uZHMxT}`I3|lpJHBc+{s=ok;dN;vToT&xccKk#oF6blbDU@q4*IbkMbnXcb&`LMoTYZqYO5QRsWf{f#Dbw8V>*> zgVVps7ACwaD3BklLJbYl4g!3Z#}^^`lv0C{6M2jB^Q7z}ny+Hy7z5TPsC4!QziM`qmJ+ac5#KfUd@#Kl|*a8tnW&00#vk_;k8!uYsjdb&m~D;#~J)a zu72w<7RW?ZXUMo)sHJFP4t`$SsH^Zu{&tP^@FKX;1k+%yAf04y#CM-xA+92%6^`Hz=jV zS_p_KCBGlcLEGgf$C^orNrdza7LfX}occ@jCtja<Y*=3nuTH#Pg4>alv?ROF^-vYg$4w$CXLEx?yx~^-VPpf58=;L@CF7cd&z%+wkHj_sN17)u^i|CAoov{?zNqX3*6YFte z69h%}1yGV*>O>H`jGjTl){G=&Y*K4em_?L3ebFa@h>@=gm7vEp-drs6#FOa%n_N!E zTJ+a&!wlnI#!=pP{E2En&a4m<5|{o08=L{rvWPuAB`U68v}ahenJKCgPU=;%b%#U0 zt9jAE5p&@p#dO5;t7mL`dS!6@+LwZ~h)bv9Ys?|zfy=Uas|e@G-PFv=79){ZY+-`$ z5TR5!@uZ?=qAy#mdZ8(vbU_rqlrHc;uyIdr+K-hiNGdbJvrrVRhXn7O2(iaPvglGc zrc9dTmXESf=Utm7m-J1M$HuBH3hf!EaBHgy=9(}EgbmP-b83w+ogc|+8+)K*$7eWF z8$jFPj1YBUmIc47^QZYME|;9js-O85iR2LDj8{*CIx^Xa?6Ojw)PW?&&%4`|l=&?GJOY z(hl(iVmFs!bL&lo3sSd5wnb^!lw`=lLJT$K;-<;OOj}OHEzAnuH7FEu6P7{PHGS99 zG-Ge3B)zOvs}qe!+~^O4#lTy}XT^|~B7e^1?k0p9ur0wf3x>Rz)9*s2BwXynj!jQB zQchXR_P2zaEbSFr6*idVD3f7Xia`gWX?A9Y?eSn@CPf%V$7SnKj*{)9m*<^O&(Xm+@$?P}gHyx_W0-pKNFFkQ!+X`CK=DdNprFj@byOSdX% z?yqz>UFP7EG+BPjCAW`j(-Keplti;}G}E}TdnRGJOx9cmq%N1#lI%>uJm-fxYQJ=51p8bnl0JZfbSj5V z-fp7@Umf9iQbA;U%JycKcTbvMy28D81jva$dLVhL_DqUD9@VIxAHlemqkd!tbTUVL zsP_28M@Qq2?nPN%)@Z*j03Inpd^`ww75%e41vj%2E|EXK&ztc+R5*CLCZ};}M|Cbm z;nVkRFl-K!>^^dQ0KGcdvj9|#6KZXr6e;74OE z1&>_$t*F{Tki2e!lCA=W`MumUK}cSL?nF$n$G3m*0$hCXI(#w&M5#Tpu{KeqD|B1d;GX^g9;BXLTpczTdemDLCT$`; z>7;E(DCe=&LS4>q>+1fkt_LTV;;xFIzUY^7>R&~Im8f$8T|l+B<_5KNS#mQa@+K>hz8O-aIAB=%2IG=uH9Ttpu+lh|q}= zD3*-Ggb+nC8Nl4S_ZqAHsN*}Nx9&pqK_j@;%a$7d`FDKq--XhwY)t>rA;k2*6-tZ! z3md2XzimMOj>uVol<+^wgV>q>!N^&FSdWS6zj&qp_w7Nzseez&{{n6QY?fyF8?!Vc z>)&9ve+F&;Lw(R6v$W~I)dztcjy+D;eV1`4ooqPrx(1r1eGhbO>;28!xWHba8`l|9 z9oDEjm9Hv-=4(mDSZ{Xqi)Gl*z@*lDmUh?1)F60txBN)yW&KaaBdd62Ws1{V8}t}_ zue7Uccd=Tk4@w#)&pt_HXfAN#Jb3E{#{$LDR(?e_Nk;z=OM_4cP`D|mkb>rYWEPAL zH7I3Qz$jwo3mT;}*-2^>+J;OHX&HpJ5qA)n_G#^MJ9G$nlSFYnq}FOUZo}E?V7Xf&gTgrm zc{<>0{$edL5nqfEIi>w@gOhQ%di0^b7zmpzGBhE#8`(jF0%h~Pe82X8K^v4ZQ&X$d%7+NnaISdQ3 z4Jn-OnkjEU5YQ$GsfL##9qPh!y`q5g0quhi-#^2?uSn);dzZ zYLOmqL|fwU-WH(*yK^pp&>w~meQe<4PT8|f%XvD-K5)P^`xz}hGn}99irPEFc(02% z+p{@55LxprNmLTC#c%99gA8=0aQRN|NUu9KU1xCi+zl!~6MEMM;}ASB;qq;{Tob;F z^7chKh&2%dy8>GVt9pvy%n>#(BAeJG2Uq7F>tnwjky-CzRJKLGU^?KNqUZ_@^X+R6 zvmYM~ZUl4inDT4s9*nho4Zb3k$kLn=e?!(4tC}Y9_pGWr(8++15OvkjEAha8TmIqU z?v3sSQ*c4(!A`sYmD$2aWXo5HQ>benjflJI+uR0|ZG3t}mPc{Gu4pu*uvT0duP0iP za;6r`Hq1PB{@Bu>v~b-zk&=@+~Wy4>s7T!qB&WHwJ{OV6^Ewe>I7U{?o1sBpTrf-$tzkH?pQ zj!0vyDZWqz4PiQBz3*0(jA%k7`iz(I^(hDXfqvw0U2M`xt9AJXwN&PSt9avQqFD5w z6a1wDG#b;8`-<)Irn!>`7e1IFX)8iS1dvUXAnkbRv$=U6fbZ`@5y&92cGWW9bZjoKjKOkH4rs<-?@kof_tv09MF)qMwoPwMbx=kV+4?Nm|vMf*;aMp(hew(TRn0Ul~BI1!iT zEq?@>!`L^s-%d@_b~x}0eDavK_3Fc9z0U@3bAWr%<1LSa$&N4zpd*jBHAf4e?wqX77lsBkH zlg;#cOaD-iM0Aj}7D`;<16YJ!pKHG*zCN&fU7FBcPIr=(cFK1bgt#9-BqCb+*6k)6_kPjG^{R_9$a5rCeN4Z z91rmJ^b!wh0CVfI-bZc1K6)j z24pi)a03RJTQS2{RGj(rOgp276oSsWzx~#G?TthbDFKjOxXeAoeO6SgC`WElD9MS3 zBQ&OZ{mT8?9o1K!k!xwA`r0(L80)G&fsK}@DdVGH0dxAbSJZ(Ouc}*|@0bZ4pN$I?w|6s+yh!qMEB5KiQ=E^lFxIb_kW;AwjiC|69hFF4NXawRs?NB z%TjQepmr#{`IbDU+{Gg8VEI?ZtGA56B~3S&m}c&^JF5HFf0-I{F>BUXuW1vujM*IdQH1nt#^gkC~0Hg z^|&)PHYEeKWabMyqbpqOC@4Sh@mpk#+2C+a!mUk+4N{Dsh)|0OYSGjg&jFv7_bM*M zDw@kmJ7$v75Gkk}F|0|bD7L9TloUDvouY!zJ4VU!La(oUh@A`(7dz-1y9=?@S8r(3 z^)Wlzlm`drJL?P9Q|)CEj4`U^rgyonYzSOz%Rn8FONih_iJZI>_U$`z<8sbi$ z%@6RGlN3g};Y^wtf*f7U54g`dbOIlF8+U22hgv7gni(kEuG)mEiW)bHWGs!O&7XCZ z#@2$e_52KQ@MLU9z|5W+E#uk?{ zFJYx4#FkuXs3|cpKWbuSjlb%5u`q-w(RuA){e|Rjb{^Kx9D2FvDyfZUhJ040<`R~N zY46CMC{1caX@I;o#ov0Ek@B@Yfr`?7FFzwC!T)T)<_X-Kofdqc;4mcvr67PND9?bK zhZ7M#q+4AWTC9$Rmje;rI!fjX%)#~#m|h1W%qS5NkJfgjH6xEQ=n$bA3amK6n*pVg z$DpVvf=aos`Oh9-`lB0xnR)Vp;a#n~;Lqm9WPpESq<7C9X zL@pHvM5g^5sZYcJAFh#o);>cTMIn-+e3W?TngI=qUf2{n1v$|cN$=N^!M%WpmH{M1 z7E&M(rtq5}#^#J*Sn5-jPRPY%j4CD;vSJB@56&|zCiN9n8kub>C!_=WTqBM%OetW2 zQ$Q^4z!LhYkwIK@SzcW}A#PZmfF_4mm?0)=XeuEg_dcKpIpoTLDwZ*%L!AN;n9^9! zD0R7_NrWa1VMIoTAv)NTca$(@mD2mImjaAzTEJphnH_*9RrEVWTwO`{2$?E@f;Cgv z{WwY{Vra|~ZDY5ofFn+w9T4UIW2YA1~9a1XyDkQgL!jf#SwGD1%-_8v!TQ4?4~Jg zY=J7ol2`0WDJ-0XGjMZ03EcDyJBpGx$#E14Q4{@Ob9>C(6oq*LOmg!4;`*SL1*&yx1MDfQwXlQ+tI_gmv_BqiLjhu_th6i&S&#~Oznc28{Jc94 zu@A3o9o=#RVu(`C!yT!x)@2t=<0TAshtP0Ba6cB-vLc)o#pPwkvLz9)ZvUJ)adClj%h0vA8{%T$bj*pcL0P#tzqrapQ_F_Q zi=I|=a({t%rVtf+Ta)ed_^G#gDyWu`&OQpeg z!xa~420*mx$Ra@BDlqd3hA-_cW5?`Jrmbk&mz~8nC^i6}8k;Yb`J~ju78Y1mSwpzb ztcu3vHVdCjPv=guQhzVC0%5|IC2H{kCp)qT7GIzE&8yFhITe~*qhN;-Bh>srS22y> zcqlQi$D2}yK#R$AfAz-*UdWX&hDIUM778n}g5-_`QJWlB81k|LU<0(&xZ@3q19LE* zikni-XgQWuV3OHHf<0`ZB4nS_pFUDc_{YM zd*KwMVcGWim?F*k`N*++LGGl#*z}^J&7tDIYGMgR0q?(te}IMQ|4Qnc!>AjK!dpa4 z6rAARD2G--vQz^d$dnntDZs!Ffg@B$}1=*<7Q( zR^i1g;Sevi$?U_Fb;2XpLCMgU#0hKO8`Le4n;I43dDLlK|y3-JB~x+vF$ zqq>lS(F;%uIF(#UkgP@h#gt-!N zxk-HF5~?AZD5j70=yw$%*n+}($Y2fC;*KvY`E^W6V`0r4bc8Ct#^T!XS&955Dl2o+ zarQhV#&%KyN%hr33hM+OJ3IfyWh7=dP=nSg=KEw#MHHradr)IN>6SFQ50P;wsPK zWP47&=M2xVu;xylDsj_DelQE$LVQxjs-634z{6bXMuBbyTPs)EJFsqkZ!5#(o-i_n zvVRpYPg;iv&9Ek5Vy|B31X?EBIY64zhj9Y?gn@FO%l#Su?2AIaocUZ#hERG%BDX;x z&(9b+BVH-Zd{IX)u5?Q(EDQ2vI>bo~E<<73d&K*RhiEzEa1?hu(}SdZw^?3@5~(Xi zX(o;r;_~O7@}xT4$mOi*maLXsO-V*Lw7xcmliCCHx!mnUQA(tpQFj!hq-j?XnBN#e zoX6u$zmg~pbC5>y04{Z$`#bTk!r9Os+IF%*5;USP8g}MV`^V|gqk^o<^-XdN9hamn z?t&-$Om*~3Vm8jCsiR|7Yh!#OMim>wjzkRoZO}~bNnjKGNf{eA928#nv(}VDtPRfG zHxsD}st+}vwPrMVjEEUSTerZz#t-WTIVzVOvhyBOlGRL59k4_1R4scRg<+az>Ka|- zo8*l#9q-(T+}Y&d$-2x$SkU#r~DBY*%`09RGTw5lv?i1b>rC%vkXf2gmEcv1t zb52N^FH|d^{d`0?V0lUT!1EN|@5EPorD2s#$WBZj&(tN$p-&bQ8sj7H)%P`D9J{9o zLy?nZsqCH(Js+6Yg_ zTjgx>I5qKOLdi8)>u`6(TT1of_G!iT{yyj4=B`y?>x^ya{ODMRA+*PP*z?LvtsEUaDPB^7I#f11UQHjUxH%t8IwA^Lm+P;Uas%nsl*` zd1O-MMfyVpJL84c9C<&%$td|&_P47j%Z-vASbg_wtA$-M@%tAIJmfIn=Y@))w&H`j zXvr1+{S6^Xa6_;ph=!0dAIdz=$dAa*s_zVKE<3gmb&Nwc-e;$1c!LeiY$I~d)Ffsf z*@Fkero*54CXY>kPn1$z&Qx5ceXhdVLS=5V3eL_5=;VOnd;g@H7Ko1Gs_QpXFKA?A#IwPhs=1aU^gj^0LCg z^)a0~Fj%gKO)0X6O|6H~6PF8W!?jrVG3YbGT(3Ww>*jlW4=D7ikCSlI2gxd5FaDc* znVr*@D9*>Ky!xuf9xuH*=m$Wz*Q74@S<{fuIP^nOPdog3mS_sCUuQ~SRoW)?_shLj z|DI&jCTx{e+yMGD6(Y|Pq;o32R-D&Nmy`f5>MeNWRqsBERhwX9(WVMS_zg~49Mw(L z-KOtY9qOOi*t!WbaB6$I>6IZNP#=4;n6_Y08R|Aj#we;czP#YR9>i|nKud4btEZ@L z7WUiibj0^WLZ6OCK)%TKbYSw%79wA8`N`gSjWg9|7Rc4JQDG+g_ zeKn$~Z^)tDoTJ@Ti^f{c28}(U-;T&zS1J8C#!@bH{@u9RCa5zPqtfoua$y$Q(o}zZ z#6Vw$)(MRbItW@>qXcl7zO~BIq z^)z6qldu9%BY&IxV1?-POjS|mg&DQ8PDM@Pcq{-n6G5yX->MBW*{Wq#|4~H>UH`Ky zNy7{cPOuI!&D3@3Q?9>WL~FR3?+%2_yo%rqxS3T@kh!`t*qw86oe-_f0+qbd8rke= zkVS?{qd?*}l+v`HwP;jdcf(95#MZCPt8=C1RlW&0(Lg6`>1u$c(0k~z#c0;Qn! zQ-sh{1Q#U%WCd)CGN7nH2F1%OgSexVRekA({NaC)qrGYAo4w^njrfR$>%2cwHa>cgC*|c%U7W`>AyoY|DKg)WnyOekMP?6HYzLruQ>3( z?U-d}1_1N2z_L$9HVzgb3uI>bZ}YOuK#2Gs9ka}U|I{)2=Y!HKIT>540%L*y7dDET zTNyI}%R~Q=mVe6NG5>2`mI=V}Kas!~8OuI`uR#~@(9u9a#xN^XAOTJ57l%U#nHSIq zSw;OkgE7L74sR>1Ljkv-R2P$V!sPd5%e~=rW`j@BmS`2Eu+Og#AvmzTy4>eLn4HSgweSZ>yNWTOwB>;wDvwe1pYQp$yq zC3`PYD{2%H*V%4DJ&gZmfiVAn=1Kqi74f$u4+wStDO1W0JR9qu*d+rnQwqFq1z-n8 zJb}^9Kij_na{m&;{Oce7pMV^&WA?wsFo89({{xU?;sE?-9;YH@g}s2Jre9a@_|&qR4cJnZzUPonUPh_P0j@|O}NRvd905r$7d*B3%p1Roz$GGKFsqiRM!^*q)N6L1Wv4`?IL6E3)3#@>q8Dkd`>F)6(8{77rD0 z)&`%%@xq4BE*3*@Dq>!)jU64A-g#d+f(Q|kBO=^~5mgDQ_`P$>ZB#o%DESAa)SD`k z8nR(MFF|%&UDvBH0L3ABo4I2BE{ zt-+M%AP#p;I6Rej&Yk+z!aL0K2CWYwUCy?z;n`vEbXI)I9Yx#(=m9Y&KW7$J@a;id zg}P%yn3`_)$F*FN>I0=T_5}QIwdk>-0f)^8iZdb1pKV~8&YVJqa2+B8e&|NqF>YQp zdt}PsZ@tIv4hwqU6nI|E*7&&E#3>= z*Gx;=pzMU#*9~6V2QCf*H8|lDZ7~txhM~KGm-0jd>t=0O7)l3=Y+!s*d$uF`-7dl0 zrYYjXdyauGUhT5JkL4EzPW#Y@2S}6!chiSxG|AaV)6y1&$M`9s zvU=dV^P{@MT=KDcXYNLuPF9Ee&`i_tv&Ql5(vwdHeg*|i<*NRO*35xuFp9_N_071O zQ`n^B6SBcqAwJJq7=71^>#hsLfrNwjD_5H3xwCbA)H4jj&a5VG=Xu6qqMJ>*ALv3+ z){85t7$S~TIy6a=1tu>85L(=)=p#;*SE19-+a)n@8AX@yub3G&cAnm3WG$1dEc^a+ct06wr$(CU3JU0ZQFIrwr%^Xx4&skzdgNX z{y4cZGV^3+#Cl?#9kG7T-rXN|Gh?o|L-3cI%KoPN>xNE;73m|@Do+&AR6Qji#$h5i zgExa|DQmaz50Y_U{#>in()~{qcAdz@#_clKGoG!y!r%K=!JoZ%TM|DY_t@#xM|akM zAsN_`%~DT>pcxxpNTwjF%BXk=wN*g@azky_(`s$9_bFe-g5#&X2(&t{Q{3@k+1t}aX99ZZeW`bqV zNJaW^;&6Feo(c;t+nI+73slGz8ko3p&6LHeKo>Tf6O)aSBPQHisQW_xF8a&h%I&B< zJJzN$t;Hgy*G;#(br(K-)JFlCJKpwf`nYAM&U|a#_>@=PuGUlkV1Up@d zP+`TRK=J6jvZ0`8p>($jovOu#+H!eV^=*QOb);!@CY~<>sIpn4MB(lb{jDozq5cLx zv?o|-cK{KeeR;nIkVF8D8djl17CTd^45x7(L)kBJvTs@Xo&V>V~9Gw3*?JR?<;B0a+n2nr~kOmHzN?zrjBqg?I9WV|b6haBHE zT8c?2Jmc87VsKg(hDc3647z3PctMGm8|`mT`=8<3YbmC?sYAHdt0H5)=ct z$*Lr8{`fN!xk?}95lnEekRG8F{knp2e@Bo9o3MSP`!&4J1jDE4zi^P^?_$vonH?qv zEE8zmn`5)s815}CQ%ZQwIKvii+ThYhOK@x%HXvW(kM3iqtX3B1Y(`2v;jVB2?GLnV+8N`#rl31)~nXBq#Y*tHD84{tp3FX|Kp+EBLlM z71wMAV_BuN(%{G=5|iD4*#+#qi=0YC-DCZJP`+DV?})%$A6`~eiYchLtd;u zt2PZYE8~w5%FnYOVMqVp2|ITBAHnwT!tNhig8Fu1#^$DGPX99Tp9{NxS;YU7u=}rw z7bDyMDD2{=WqyR+@HIEc$YX8ZrAs1Y*Ws8Ajmi=1- z)=xG?9SzLCH{hT4h}nxo+uvKA2(C~qd-MP=%|+5fB+vzN$ZT?6fuXhERYL0T&Uw_n zfUhe+H1sk{C$Xdf8z7BLCtZCHB?e(^ny4j3-RFR z(ECcgj*J?Q;}NNj3ZuRzz2!c$p3Zuvv_^Qz=qzlMd;o-Q6o>B*dw*5>M+~*q0%~z~ z|L)c>fB8hSv~t>g1!WWtTKs2X@Bb3q`mfdTPemTXzvEi}a18l}83zl?kE;7$gYgH= z`p5X!*Z=XH>8Ec0@!9{X`u?SK{}YDwb6xQx=>DVm#*eedzm@m@GT&hOpD`>}Cg%TS zzOm^6<)*aQcB0{V`TKg3C=D9I{gRj%9-UDiA0NOd#0W6HQ;f8ec$}DN44Rl}U@{2) z51=ws7&^Cg!6Bt^453D3nJ9-+>Ed`>Rf$KbXy=k;myU+a`J<49C%ev&k>hvMQ??P} z?XCOu=ig78khCt`@3-xmCKiNqD14x`XmAJTr?>nX-sc5|pqUEr-G{%I5cW@Yn*iwF zt}k1QD3@24H4bkGgg3&xXIB^}Yu<1k$OKzaaV(h7FCUVSI#j~smTVVv(ES4b$SMOL z%#)_To=9BvPO;$h-#C+4o`hN5NG)1sqU7r`$6ehxvo>FbfcIQ_v?1PI{w~rQfJbly zN^0oQgGgAj*_PnSU1HA#b$kyoM3zqUU|%n?dN2c_Ul@9&`HnF+0TNZSXAdDiN$pnR z)3qjR#m2_6(_>Q;bnsA-5vEDG-?85}URqJIdx0m&dr8yA8)2+@>tkHCOi10UH;cK_ zod9SB%X*?AYe8?XRt~67M+KjyKu^RkbDJ^5q+7rC3AXrX`|oWY$laqi#$0&zK--pE z`3L^ZY83rF}{{5LDC6P<1D@4k!6Lvme z9`9F|2FVR@l0MqhfR=cc?@E(N*GmOVu;Zm-alSeYY{AiPBf#xLljYR;E4KbXZ5)@B z1oMEG`0WtgS||H*ce{HR`$v9>NZ;A27LaAtxxScbE%bRdX0vEGEELI2jm>@S3I_5u z!?vQ9b1a7(3z~l=zj+uOWUPRQT)` zi~{<>tXbwk)K?^PA*;{ba%wrW!A+T^@6NGbv1$H@*2Eliro3)k&8&lkwhzBgxXQ@+ z!z&2)Uv52|QAmv&0OnpW$tO*NhP$S>0Bn|ah7l93!e;eIO4Bsa>FB5!t@=W`5Z+wx z)A7+i2=|AvbehF9Aw!UH^46@~fJ`j!n{p46l>$*~+KxiRdl*`2#ZsEZRP!kq<8$Lt zPtc)@@#Zam4wDc69HyWog*QN&PEJ~lBs*wn6^=Ke+P$*Rms8SGW|@zT+-E^ip(SzJ zaa3#7+I7#1Y-!#ps!TQ?mF6G=#ROf;GiL^Cy zL9{$Y3ibKe-!q6pRi@GQ8koy}m@|Bj`K|e@oddF+VwbG|T4{HD3DJs~uNqRrfYWO< zuDIzG&7M`soFz73<*)mw{g}J)V123&DpQuGbrKaivI?gE@mxV`VR4x`5N-Sx#f#6$ z$@X5?#=7B_|4!HT-qpv&$?a1$l-_(apCg1@8^&RNa5XpcCb`g;H$jgrNNC9-&dbdOE2J5+!^`J(f3byR{VlS2IS zUz2LdOUXJiRw4D&!_ii*_lJ;D)`f9HCd}L6)Fw(=L9KdbBQZ0{I9$W9yBBbD`&Os2 zDZEKvLa<*Cbt66!J#!3J{S$>LMLoU8#+}gm+-Nx@u@2Y%IT<;DwIgyvw4D-N?~9Po z`Fm|z-zz>>zfZMmSH(-|$oPFd4jfP{8Zr4v_~cT|fMenW$@3J=@%xoEtQ7wgNC4e% z?*Z!qqtN2CF-yBB?4mTO-;amnM+rdDF6;?ZHX~;T8P#LBN}S(D&Z(cW^gP6jb9&%j zC)r?V_F=F}>J$^1|L%#{hG;a+<6N#hT@B&3K9$OcIWoo;!>a|6CRXe8JtCO@bT=+q z9W}8luCOvt$Dp^DX)bu(D3WxTB#wrt4ocfJGB#)^x7*lF*+s^Zt)M0zs(X@NZ??9G z-A(XK{OUYieOfB9={9`Nd~etJ_`KF#;bsO)v7-vf_I&aO%kh@+5O{0hJwDiLbnx89 z0h)?liD58$#A0oRo|A%92D#`$y08}JDBV)F8kK6msIyY=9XTB!S^%&icJ$W6En}8ellbGxK6}J7c zD(`cD0>28#39NhvrtBGqT9mh1Efpxk6b4(?%CDVC=3#{tCu7a5tLAaFaWdz~943nI zpZZ+}_)$&YP@CYv>a~4nVK+@4>RA-o>URXo*K@old%QF6~FG9G{hTYpdzM8R_4*ZH}f# zRh1Q$?VJ@4J@Ve7eB1XyM7h`Q)zp2Z4DtL%eWA>OoY6W^L(3*IY#L?yebq9g8>4@U zj`3$lA*TzA^dbHhcB+?VwVB?~n#*dh55V`X0VSzKG5=7qCR zwdlD>a?W<`R(F_+KH*yO<2-I3`sA1v&4{&1X5ze2sASnbb^hGh&RaonZQg7l?jCy7 zFFsEQ>{V7!=_F3aaOS)bv#oEjB7R@F?ZV$wgA}FP2oT$s^n90zpJpnQwgMI{7f`Dg zCGK<$Tf4fuS1v?SnTf?XWXLVgqM})GJJzN2of#;k%Pi-OEB!MBYzF9se=+ckUa>PfP)yE~N0>=~gV9UiCqzB^) z1$b3U1NJo!$Zwqx{Tr}Q`X1#3aOXok#uEFUwrx&iwJLT(kzbGY(dR>vraQO#d z2azW!7mhAPan9e0Kdt2`=BUSBjnNX#Cfb&-)oRe{&}z}@*{I#9=k|6Vb~wMA%ygLy zfS}DAi->1Tr4z+`meOCAeir4SbmlbmW}i5v{ydqwu#=Wf@@lLgjLjsj!J_ku+u6ZD$oN5$d4imE7lL{8(Fz;?!V5bP`5 zDH94Zo|Imn2M9(xps|EChw8^ml9lrH3&0aMCt+#NeI<&<4Yx5OrO4^Z@I+GbhRZM* ze_uV00g&-*23nPKwa<|YxCisnFP9lH=y7MJm(UsJ1n8uzYKE{jGNb5*x?9`>Ms<(d zYu*g#XpHJn&2`=s);#I;jj-1f{Vo9a_l^cZ=>lc;jl~O!+oXO!e=AU&Ohup%coMj{ z02D>OP{|QP4Sy&w>>Xf~GUnjad@1$}vM-YK?*fxm0_}-=P8msH{;I_@0=&|)_C{+p-|w+Ss|(_k&<*Rb2@%bR$Z6kdBjw4Nt!Mw6alzi$m)o9ARW4_xUG1e z{v)K6uRA&_><>Cl+L$YX4qDc)eL*xT^i41VS87xq1&0w_Q`0Dh&dCpqa)z0bN4TrSX94knYG_ZwJlzv~PJK~C-S zg9Xir?*j$Vhxm^3mE8mP|+tY1Y1^j2hwM zhfaYu ztIwdm4~FK*+|_u<<6?YI~D!MM}o zq8!MJFKwHY3Q>^2Rtm>w=(;HfA)#A!X|D5dJw6vUHbW~=bL$7_-|Y_p%$!SLVZV-b zdfUK5C{HfxgPlf8h;b^l2`~732;nF9nT>K?2~KiKOI1aX3%td89uPCdo4QhX3r@2Ux#=p;^4 zOy)*OXvY4EL6TyPAO%q9d zxQXAd=^#sS=s(a26mQ@G>y33E=2)vrMa1l_a#tf5?|vMNmhefY>U?{AOrvSTLi6dW zl&eptt?P4`mm}RdRJ^h?92sx2H^eG%rb9vZsQkR3y1gUKU%MvXdg#>aL~HZ~+X!*> z5LoL0wb8bQI0GvsDa_-{h&D~4B+Z^E~b82B^9H+5&tnZl>aR7JsA$%60VfyI}|eK)K2 z`P^2;=X5*aCJf|AQ7LpI@pkIus4xk!?0pVCz%1K3s}*+2`I0>b1K(D86o+3VxnTgK zycWhi{Z>g7$jK$1$}r{4HdzwGl#c12I^4s&KA!uVorD{XE3C_%D;@W>hcV_7wGV+L5R0P)H~-*kj)5ID#IRL zN~*(kTU%M-BSQ)GXVtGV>40W_WH8&IlqxZ_7m44x9w9=N1N%p9cUKKJ?rEemXgguu z6`wnMT&b~M($9I(8njpGhL7(8>_PZxe7Lt9SEf~x!48f6CWLX{O6u&`^B`ODe#D7Z zA_of)X+U^%59Z-rS7lIWNr{?O%>jQ7Gn9r2z=<9P;-}&|i6#U5;ZjEh+CRVmkG^1p zhJ-MSh6`Vi>&6a$D(2UlXU8UY3S3NKM2IfOe06>i^&kR}2}m5^hm(X1KEmH8EcMe+ z<~K?Aws$LLItuo{7nt>Pf6cBxCHKQA*n@ARfn3Ce&nnu9Jmv!1%3cyj+u$v&dk7JwKcW z(LuLC+TnN3W?)VvC*dV~xYnNlE+)jM&{FJM%B;Uon%yy@PrnlRo(P9~Taki@Am|0P zbc$5MW!(Ha$%X@Y;LC|}&3^K?$eyJWm=HmG!os`a)pptqBE$X7awouo#*K?fubVILkk7kdxUwE z)*!_Vo`w_i-j*d9#okXq-ai)Nrv?adq#PIn64jz#VZaL}YT*b)fSmYpnASSMmy8!S zi-(B)`k=*!n!yWy-8YzZqehiq8-u9}3$Z~^#8NBK2~UgpC4@Az2KJBat=OPp45$k+ zzJ;)EGh~6u_Xz!f?jZDsApk>sZgo07oBn}M1KpJxdM##-8ssrVpETqB zIA4PLwA0c&F9WzKe0VzX-qIS!iW)57K(!#R>`6S`?K;x*(U#R_f%YsCUp zE9>&dYR4A0!FH9pwjy(D?dTE_YKNBo&QaRxiu-B{i~ERQvwJoVHt-o1!mj(E_RiXd z(b^A{wl=qo%@NWx2HJv--dSKvXP6b|>lSC2su5H>T84?Ll{J>7_kaqvNL=N)<@b#W zMljjQXUg=>HKi3b_cpbWP0m{)5e=wu?L#K6kuBBjRa={ctSwEtxK?3{YPmCfhfRe0YXpICE;4C z9hR3Psm?m9woqd`{QDIyE3K?7aycz5EA2hc(=mroaN&o#^0$cYLGzWCJI*mL45B;w zy5{CN`GW!|_M}P!an(-E9~xWFFAXdkO4?&!`C^@EvMuNW|Bo zPW&foOBq)L5ZG>@$6^=*sRv=O$gNYFX3Jh>X|c)UBEO@k`cJ*w`W*0uf@ePjr6JZy zB4&;JZpvC%wf7d+uZV0F;L6+9a{zrR<9)~49qnwKEPu0rw`Rl*2M?n%rN22YM@^{-*r!Y2^AIwpJ%sL2 z&*ecsi6ph7JwN_pU}u2^d7WDZ8rj>ol7THX;*S~@uq)(6mEdDU@b<37gxV}l+Dla^ zFP7jdlRD%@4HL~%2yO=R038Ql6*Nq+pFYhQ zP?(J0BS5kZC`Etj9vXlox=+Ec`5$!S7g_%+_{?KnSDBjz25LkeKyLqyHo!J6`@OQ= z9-E)mgi!<#8NzT060u`IvjPM0G@0!5Cm^S`mF|+Nz%0$8E?{Ae0PM>P%FE@?pRhx4 z8|EVdaA6&GQiWv)v@2!>(Nstg&+yp_af)3d>%GAKbwyZ;r&lKYJ-rgHq2;PQUJvU{ zFLC&K&r=38<$VuV^o6&3yuADrG)W*FNx1&Zfc4B+WfR;4uJ%;nmY2Z7g}@ z8fZnAJGwYk8k83Lijhs*jD=o8s;Txw%C%3`&ko&iFF&+z42jU2E=P@RphGY*S7yc; z&eYeMda=*rcV>i(s9a0NAZM25x|#?`?PCN-D{-4ZXu{#KG@WfftV))7OK~^GvjU;B zI#El!BBQ{oO@Ai;;kLvci-c@;q455IlFq&d5Rowza<|6}jz06x09I*N%8S>OaeUnmn!i!;Ir@~Ql?CDIl0S@Pt@sre= z2cgft-P#w3!^+5^Q*9>^)kXscj^3Yq5jMA1)>`VlMV)oeJ04jX|y@4V>sa(-M? z2yHUcKtzx~a)i&5r1{EfqJ;qzpA(}Oqf|NGGr2mWd7g~O`ZPN%MW#yK$pdAHmmfnv z<3JFMg5zuuC{GTA*`XNuEPM`dM${jO=%ORP1xLcf)e^OGLvC9#Z|S9w%rS3WgK6*z zhJ1r}ou|xEJlzpgh&b-?vt-%$Qm=&K?hES0v0nD?F6uV{>f}U>=(}vW`s_|ZM+xUM z**f>~Ws-BWBEs_uxZ0PMwn8DFe*|o?3uA5m5-ozDw5&_QJ~P}RdjC0AN}q#03dIZ9 z$2kZ3JSGL__BV%_QpIe_bj$m*)hk`0Sy0~MDzOw8O*Qu zlo^B_%UC~(8L(8}bmilTF`UQ3@^OTw-QW-vWu%7Djd8nBd^%7f$DHM_rc0jizS$U; z&?Fc02E_!*BDMF^HG;XLWRNU^FpB1ZndmgYK8>K(D*{;%-r7)C)S((M)vEMe>>F^} zbqDk9aiS=ONf(Cg#@ID>QuelfQ6aaC9yv8*?qC6+{XXYE$AE#;vowyQfp!I|TpE}! z=$%DctepdOb5tH7C*`p8Q-|8oExKq2aK#xA zeQjZqp0(d+&uM}zu_-2sNZYFfjX7J5s&4LUz}V49~YC-pi1n) zSa?LN-ClcvR<}dPMOGL`v!miuq3Fb_|0y!mzPR6PW1#coUR7yWccL$6 zWAY=oX%^~VtmW8kC2wmBan_N)tuT+R>U|RJlY-tk+XRRI6#nFCu}tQip}=a6G~F(` z9c~=@w=a!dafRP@{%&(9afwCJHn;dTmmO;=%ks+%R%Kk-qOe1%aPUdCTpG+GYYOeq zIh5E+IL!9Rf0uT_bGS;r7Af1T$$30=phL&ImNGepWO)ohH-6M9o|_(qC}PUHd!(p!`fR3X*;`4{TvT1f zrj5VkbP<)pw54=MD`x!BG z$Yz{WeC50UnI3rRN#%tTCCYpLF|Lk=8{9O8L-Ov6yRzM6JNupTdGA}&wpl$0g~;I; z!tERK@j&_dUU9JCNENJTI_gL@)*y4|DtLfF_8Oi84HsV`YXUB7OG3sps)%tQis*h9 z&b&KTaS+bzuy^YjjD*N>OZfeA3)8>+1f$NeGN_>}7oiLy}21k6S$LXFM1Z^Du zb3AQ{9eRXd#f|9oP(fW2e(nkfzgr#bbeZht{@Ji31#7B4>s)cLJ`j=fsBD7IFPHpXg>>EkFHetA1I=n1Vo%NxB6yf@~II>FtmpE}` zkmoeGe)z*vBUG2E*tJbJnG)ecV?N5tUl~;n z@Z=y}yiB;0*kDVdRq`l}PyMM$MXfj?o937Z*(yDo_KF_SxwR3F1lp3gQB`82_~3du zTBpfeIT?+mmB0kN`n(nD(u!C^8nbv|T^}7YY&imZ5&q`&wiH{|NlCVmzsM)3wz6yr^h!ZHfvwD6F&#DtZR zP-6Ts%H*jscf0X)@!Y@0922yt#?rD04tfKJLy~i{tr3b%<4zf6S1}XgtO-_=N}Rot z|43;{TlxKE6=Fm~I44Z-zYmV8Al?+GHYw3-lbEcvbU{qC@6uZnkD_O)CNuXVrO82m zAnl8jeIU&bbdFxbH4MznDMlZ&Fnna>%mJ$)CD3|_+EV0`}pPoR~~ zcek6O*Xw@|Awl-S{Iu;2KmF?a2KNaz_xD{_k+x&ypYc2YO7pX`v$Fi-{eOU8kUt(= z|3<_7A7L+{|3vfu;9k`*4f8zNQBy9re;rX63`zM?b{HJQ-;S~e|2J`X$JpBTO zqflT-CV;ZhjUBNrqUD=@ntWN!uC@3Zjk$cYIOz>Vg(X4)Lw&#b&|7VXrQ8dWXxQ@> z|Ng945;$|zyk6hGP^wQGf$!B|Ibp%t%r*WB3CI6pK%6SSxpGxtaoO5s`3Ztl`bU^w zoe?6i>VDz$*d}1c_!7%JWyE=XJ*mgUN;hlINQywB+jlpjHugzBsvns3b4 z(q4vQIq&--3g(cNIpXdo<1|v6yp|yqa+pSj>ta73*Ut$R*6@T zXZ8c2jj$U(C!FIhcrQy(`u>kG?kxAP-8EfY7jL`$-Sn(~Vh^9M%oj#>il^_!&)|k4 z`+h)3`!H-td3L?u!kg|N?{W8x}*@I=MIl@wLj&YGJ-)GBvu5Ot8-VNYD*th&o>XiBavZ>(z zSeXA5Ib-^djRilsPe1Np|BvIxA?*Ko?mvF>zn%Y2(6;~5(C{x6|DVvdpJ1#1{TyKa zpBoyOIT%>~qr=#xCzO_w@z%|K=5c0QCWfAgp4@@UF9dmDR0Sj|FkoalKl+3Nh&JUHbaaeCA^@B=TMl?DV!6(dZbKvRp%DoD);V`zk2k`Jk^6wt^OmBKLLQIS zaN_}<7PQ3rkPJI@jU8b6-BY%uec9?c8z&NknB41V9%vYT+|rN3&D{eutx!nvG;*6)%^G= zPq`GrWUGJV2Ga(4@{$j2Mto&8A|^hIyI)a`c9PIZWM?L2CFThz%AOrEcHY8mFy-$3 z6|y^!cRGj9&>hb=AZO&=j&_w)34&|qcg#mrLv8^%g7Z$pXeev~Z-SOX7~R3Zthz(M zg;35f)ETxNwb14QV?N0r1%YaVp$fnx8iZuV)VWdX186%$=HDLp!sCQ#O~}oLVLeph zUt@SubHZbAtkFyB*oK+=4c^NMaLh)87aKIMCd9~wc;x5N%aY?goG9OK{?zWL@v8yH zdfCY=zmdW(Si%a-2g=nPSNQUT_?1UpXltP21^G+ehf$+M%x_Zg{MVC-hlpZe3gGoa zQ}(WTvO}kE6o%qzvYt*=u=5^P;X&FWVJ`vi-ZmJ9V#0de0j8 zmXyM?r@Jx=JRR%X0eK9?2~%-T&j?86QsH|@{b~nP=u;%A0WWz1%>uD!$g&$vM%x-C zZK}_ihk>L{ymT%10zRu!5u1I>piB7ZMzgS~QC)#_Nj0)YJMM8#ukv%xQK#~AB~_O~ zj z@D)8y7H8WaZxu4D=1umFb33+Qf6vBW69PcnP098@5r_khk7A@5p$Zfor^J_tF@8F| z2C7|elddkg+_w*6#?WN13t>aH0%L!Rfu>K<6}+=!2ZG*{f*3umXjzVXlF5!U-nby2 zc)*{`<%uPkVnwl~&VYXYMolaQx(Z6Ig)l)bIWE{SlW|RPpJD&iOJ0vbSQ)+qvBXtL zrv}1}mf`3)9M!F_CSjofYa6{MYTyXzqvT_Ee*|`jb<34PpG>Elu#Hmh;d3i?ekSVT z^|1wp_s9+9gbVzg3ixC$vf4}@%^x`lI)}NH$6JWP!dXbwoZ1fOdiZO}QP%~B$9cmF zBc-c{`)*7O*3M)v$tZd;)8KE@R)C{pK3F_OI0=Sk_UXkWS1TnWQ_Mw6YHZh1Lu^h< zNwEez{NiE$1l~Q3A06ZnVXQTIy}_r&=4Zeo2elLCEma^F4bE_reVvMo>0(}4CP_Xy ztQ**d9|kgvQYMo(Yz-Z6N#V*I*`Vj%`o1rQFM&>~AL$On2Jm^18i8O&(Zrl-n9aek z&0lNhk+Wl3z=$ew2)>ilx+S|zLV^Z}!y|keL&1p_r)#EcH}~E6*TtSr#V-Y(fcXyI z{x#UE(|0!45XY8j_sdZjwhN4Sf7?OAm_ejNI9S__9#g7CXH@zpS7~H3yJi|0di{bc z4j3C@tO1r#AzFpVMh|{8RQ*&?jm&n{LQ<1lQdVbMb}U_={oz$MoU88B8~q9P@@>al z^Z8?ro49DWmCC~<7b<``|4}z+RbExIc;hr#9d%&gJQZ>`FZt+=5HWt#vtzx?6>3Pow zJ*oIMsS*lXmtHvDYlRNdv)H8RTfGYS**E~%MieL$m>^H4-KGc09fr{GwEfyXXfELf zoxz6*d<$odF7=Xm)G!U)d(MaU-ZCPY5(b45q|1d{n~e5lA>PTSbv|-TVLo{!K1|Bo zff87%B{(HGOi>&KOGKXebf+`Tm&$J@_Dbu-(fd94ElOA<+oK+`zX!I9e-SMQhhAuX z>XztuMz^VWhIz+q7kCJHh_8NZ`RHzBEprgphu9G$fB_(b2nH$D9tELKjZ)*v@$}>R z@9@WCQEX;nW@DL*LjS}Wgm)}^~u(m0e&P^_80l2(M!M!E!b^h7?xP#qVq(WBxxe@L`_viE zbuhMpOsk<2v@DO~_Z@e?!^>b6K!aK}{CvM#F>r;(HRW}j3wystpdpE#j;+i*xZq7& zB59AF_;Gk#+~Xx9C{jt`VtgT3cUi}5q=xbx9Rcem#P}Fim}%zF{SbbavgPw$bVnvp z!uz{L^a}4Dd|>-E~r$<=18PA}@~J=8bFH%7+T>b+=e_V)mn=vS+-kLXnb zFAy0nST|;{tq}u;K^7~nnUsj5)c`Z<=MH#b__9WH)h*&_*l%RRfD^R5dGqn9_OQFw zzIK8k3hFBt!Gk9H^^Vhx6gGZ#X3bt;>-bf{iBOLa9_B_Iof^2`Tn~40zvU(c2%;n4 zqyOBjaLMfx=jc2PchPk&omy+O6wI%G?8N;23*niv)f8E&-u*&{_vn?g{-C_j=C6VwWuckxf6p$WjzO&eVYKZLCyHcKp1Y=M0v0~Ze$0T+YjxXidr zcAQCM3&{$ibpp*;vKFpxwp_Lv?H{r~WGN-?b1FkEq>ZG_5>?_A33w8gvK?{B@a&lE z$n5lV`Z{~u<~j*veTgUW+~QP7Dx}p(Dx@&kSoy0Nw`$;K3m+k~xyj7w;gVeG;Srvf z7gwGevCb||QtVFOSBAe+=$|Kt-N7!ZmybS{L1|G9X*wGrs-XN3UZz@DM z$3UDub`2g~3|kZ%CNc4D-iDohtGAGWLjpab3}IOKU>pH)^5E_5TVv$|#HnjxOJR+aFL~GRPk}c*@VdwV23iC%J6=}bjw)gbuR%l0W^6HWck73fRi@(P5)tT4yX&P*hzo__a`?HZkPov#-}*n`Oe}G{ z4G&uXvpd3fhQMw>E|9K=BTX>-? zemGqbDm20TR|0`bS`|FwT1-WGN}1g`F~l57V#|c4vUcWAIfk(~18mXZ8$+l4sMXz} z4I_og^%uat;yQEdb^-4^HM82__5KR{4i)>u59mAr#XOp2<+IB@DM1zo1GJX7)|cRZ zfhhs&f-QYDJ*QB%Jkri2P5$H?s-O;Ln)HrFnl+O4qBqn}M*BMb;JQB@x@u_M2-bt= zZK7kSU-tTmCW%iBSu_<>FGer0t;g2K&57C{w7VQrj%(WOm&0iNzWrTdI)}OlKcUZ| zct=}=Bd@N(MS4c@ZFQ+%d&odCWoIuBiA*^@a|AuEN4!1k1Jma=L{O*i3S8#rI^e8~ zr~xl%{VHMN@EH9d+Q9CxX}1L06=uI=gI4tFgXU8QA^WjWt2>f1fev@N(JE6#Ks7)_ zgkwusc57!FF`4&GI;C`27N5^5N?MwlAvF(ks?W`J7299ObRF-Pb~WM8qC+cXy7Fwf zH`wjCFCYg8yzh}a^JZs0;PUfG%T1|ZLgC?_`M5Jdd=Ma%zuh#o;O{jM@FLFW0k_Bn zDdgm=iU{m86;iS%PGLrD&as%WMFCYvz@LVP_1)k|c3xv*!s%GMUSYpLct$Tz?73eL zEZ5tNQ`TIUm2~l^6}FzWztqG+J(Dr6e$u!9TJiOV+%$PO#R{X5ZH4X2bqA{)lX~`g zwzsR-0p`=slYbj$z*r( z;hubTfAA>D65YsAh6dt?UgG-(CZLIxFbHgOthBS{6S){d*Q=4juv+Av&`^Aw^U6BJ)CVVIxv1Re`%Gp7s}K@mACYr(Ye9q*?Hd$zIk$2!G2Soe!; zDrO4P{XlO1VQag@(Rj2`3sDPeQB6kK_Au&0H3+y1mGd^FSWR4GO#J|t(~Ui|U(s6l zzWa1Hf=9IZF=oX>PLM07eKNF`5yDwI!iXOaveZ2Le&ILiq z3C7mJK)l<(;Mxabe4}6PvO#;KCeJYFlXHzT2QikSRyG=ao*%Ei6B!^Gax^(5Cs}YD zFhUeH#Hl!bZB2-E`$?m3dUl)an)1fwq+It`*dLxv2fdbDw`%hce#`I>;kA9nBqoyW zlidPpMdoAyx6JQ6!e^^~}xRj_*I9|06BNW{}^jY@~wM%!Qp&y)UfZw_< z_#Fvk1~ppvjwLQHlil-k!Dg%0Lhwy!7Q+JTdxhw7CuLo z8Ouq_NGjj2e?LDswN>hOM8l1^1kygTwIR8G^cYINq)Zz4>FY;&Jf|bWhTiA4fnIAHbMKw$jmpPMS~k>3(ERU=w)87Hk70Y!q?b*|TSKfB zYs_}ds_j!9*d^PsI)>eXMh5w@0qJYJkeh$x>==UD zc&u-<_%MM$wuU+F-0>NBsCcMzrmgo>?j=@JSA@)6(673F#FXe-Y}qf1_Wa?Eo2L7? zA2-(CI)-bq(RrHfaGTLR`x0FFYN#_*p{;fy8IIz1+?l*?Xz)>2^7`J4oI4f!P8ciXGPpefYCS-IB<6EGI>I{)Nn-W@>4F(iy#G-El+l!E? z(8rPO!pD^QxzH$@ZBx`v&eaK?u^?|O`1K)49f2aW15PV|l^4m^Fk^7QZyB!>>6{sI z@@j@XpuDTD)rP=4LDLu6b~re}Cb&8qaeb_U$z~rL&*}r;^|DW_K@&%u(2tYAd#rG1 zoMX4|<3ciaOH<=fs2UZk0BQNm0E-R-H_^UZsEeCdy)e zIafddXSt-2BM}=DDMU<3YLjXdK_nmUACmD%jfyHZ=Qy06LVwBjTFw%C2xQ5sWb zT?52p{*6C`T4vso>#{%4=nIb)&$m}u_xT2vsuM}w#(_HOEvXN@`qnjJiQ z>O_ z$W{wu)`?+e<*y+TNV_`sHo^ciH^W|>XMf==wy$>s7~41wLujX&3(DYJ!{R0@m$_Sx z0K4wPoTfQS6Sz>Dt~vI5()!p5IUYA^E20v9Ddc7V9>(glvk)sL=ahMs5L0* zW~kpNT3Yn{dDVzjx4MF#r8Q>Z7Ai<%id!4$Zr|7lV;k7{jj|E4hQJbkzGkU0kF_&? zU5fQKBPcrEG}x5c)7kdq?-}j6jXnz-ObP{CPq6JsOAm?fH=)v+OZ~e-$6RDW#S2Fz z8Vk0x|D;jWvZjith^t84UwsN3^U#MZgc{gzJk&s^VR6hzVM>V-G>u0}pO;Jpr?HYU z$*90_%fWGkOQJVroj@tA83vo-GnP$(jGY3CuWd^@Y z#tyyJ9=!%4xCm|Dpd=RRdN#Y9ohJNyw{K}(CzRLRO40FMLB3l<R7_R4lS|jQVed=4|_rcQ^uV z+|b73;(N}w8#02WaY{mG*GAgom;3vk<8h?Edb(~~%%ceBiZyDQh@FWh@>0w=6 z2^)S0p+C6OT=E1SvE=atzT@@TNjq(WFXie_wJ)icCwb8WtR%!N4yl(U-BmUpZ*?iU z+rK@-$y!56j7MkF-cTtX?8BZ+H}S$y64@TY9J2Tu9TFN zXE>A8zMX$Gk-w0~aK=V(Pvai-^2>#jM+{%{WSG-}ovfS+*j|@iT*xZ8(d|i%9j!UW zh6UBFGtEdgoMQK8Zh7)WqLtY(vug;6+Psd@t#+%edR1c|yL!55Z7Z*eiMdT(4m0Ja zPVfB_A?CE^b~AB6yWu_6QS^g;WN;s6N|4`b$JMyU5$E2qf&GxJSZR*6HS z;5Vn8;%%&W)H0(ki)@R|7itFwjz2i4P&glFFHY~3{A3*MSg%?XmN|7MA3t|m!i*ew z_jC#S+QbfhkshbNV$>yfg=d?W(?gsXJ`qFxTPr=dKDO===Z%fXLdvu_&`_%BhpxiZ z#&bUM#STVn6}Lj~RB1B{uTlb+OnL`J^4)yAeeDQC&?*qUtR31#l3oYW!QRnQC6E)N)5yrQ$xHIX1(-Se8Rai!czAmN7KzKSbj z>>x|gdzyR*?cTw8Q!`_Ne|F2$Q8u5O=p;!`B$6y7%Q!K2C#>5n=E-=zWBdc{Gj;n9 zsv+bbD%X?e8nk!RGzl8njC?$QS(xwWVbY^8OCbsT6G#3SdOLS{%w>q5G&taTq**=N z-@~Z6c!}R>Fiai4RB>u3^15YA`Do%p_3rafbCDUYhw!o6!|iGol^28_`D{w`)hfMH z^1!Mp_}reWm4xOahG%c9jTISh@8p7>`ttJe=+?lO>7p;3hZx6A)`||06M1)174_zw zPMlQU>=*I+VdG_WZ_lJqt;_=gT%~s>C|OGR1%i{aJWi(bg4ISsIH%^u&4~#Ko8zk6 z4tnP$d2_ugkmLEXxa^(}*4J*`^tM!TA0rf^ZMai3dC0DXRL&3gPpN%P?+@SBzAzAR z5tKS9JAOd52A7c`;T?E7TT`K7Xa`f_L+iOr;wXj{D}X|p&SxyC&dPx5wgqTYYloeN zOfr39B@Y?Uf)9;5CoRpZHeQ_-OrFpdP%L`-GQ(R!lkwhrT6&i^U1uuL*fh~BeH>gS zC2jU{_Q;X>hN&_#vd&T#R~RaKxRuN!b~tHLLxP_HpS^2PZ)7@OvEN3Lw6lhxM?Sk< z)|-|>aytZsFGdiq9SL6r%OAbb$yq* z~3usKs2GMD50?u zjAuQ=mb*y=OWDns+of)=D8Ub)@+@1o-0XvUGKNjKAv?(j-vDtJyBAVpktJ`)MsJWx z-93u&Tm}ajDk=&p*SM7RAICGcaiOkPo(a_ND(qSiP@|mh66kkMaj`=kZgKOD+0@$2 zcms+((X~mDJBCEk-$6Een2Rx0l)p}XrW7|<^7uAMooU=tyf?O;iZtQ>JR?gjveFT% zNp*o$8Rc!aW2vdMP(ou!nOcX#g{g9kC|~R0ZE^TQKFIF$JvMCfo@B+Ic*vzk+@048 z^F8ykXEu#Q$`r$Ca+lI=_w;6N+f@T)Na1hMX+n5z0ruUGdItO5TSSJ7PEJ#IFF0HI zs+1{rC(kJvE0!6=DRna(%lm5Gj&UP(a!4UXinmFI0UwN~7*1dQ=sxOdxrXAhBXlvg zUGHcQf&7A2j1ymF36!WA#pOx9dBeZZm&Eg->;Hc6Hto@rR6nVuhT?2s?>i8@lHL(Pt@ewMpee)q}%&z2Vx3-K2HRO9?k#cO_!>P~(t-)5fZ zGS^lq zHtud%!4bmB9v@k_of5(2hOO|oC!1XgY=x_Bl?X#FO0fs)tV+KvC}e1WIov`?Z8qzY5wt@PT#6{dGfOs) zOVTWBKg)$zO&ST%)=bN#;T95vu|joWe1-IckB#9g#$d`90PJ0PR=lWwR;c>OqLE7; zaCcfX8nRrxP&qr{pt17$T!-YapSyl!<~A4B(6l2JJv3^cVZ$dxArzN9WfsL;56ecP zgc?%#RP>!m=l5Ja0tBFmCY4*N1Al`*9{i@wQ*%1mf_wUtwB)VZozdc@+|<_N+q|Pz zS+H)y`PozpeWgX@7EA6m>Po!q3LWgImv#qv30EpdAFi9GNK}UG z8x1QqSLB9j=%_GsonDwLt}bnTW??NU)+maVy0zt%Q$LH>AP@MZ^0Gc^QtZ~fskvmo zF(}{DpyYSzc0wbaeaA}E(J=e5ZT`NGTD9_{X|@l?(J)V)scLuBU@bbMdx$5d$Z{|= zraVaB0fcGq5IOzuXg~vNL2M-C;-o8R3s!r+0%KcpBqH*Tg^Wr$Y&9WnZGqIgV5vd6 z$_IWl3Yv*iY07L-yqO{HCfh~y|5C|3`)!}o;K`1>IXMKhbPNB9qZTX2Wx=_k`vxm= zP`5HVz*|Jg@~dGrF73+-9ao9(6V8Vu?t+nSJm&V!O5oMHQMXhx=}`d^{3N;$LGrt{ zrTg+e5q(JSgDu|nPd-(odL8x86W<&>yKvn&`WXarH(}?@qf@+(OY(i-GUpb@13GLL zJKw)S#_R8l)v;aCiEt`0uB%?C?xkzfKy^9J@e9btbGCcgrL3-kmyNJZxAJ22XAIKu zbQrh1(-z+x5cgZICynozVn^id3 z9C4QK_5JzxZG8x#-YmiNf(M$ZjZf_rnMK~dmNnL_A(&`(x$GcPV}9YGe3}(Y9UpMO zn;s!Bd368vr1pf+1(^jJo04XA79C^cu9JJK{3z(21>cPW?SZ^%%RTqM?g#-{D3ptD zQh9JEAYfJGOZ#J&1HAp0@+O;dvMZX5QF~9Xh3|rk|G#ymz}4fY#V{uQ9@{o=H7t zQ2f;*WV?(FT#uHgzS7t{>28Tku890=&#cT5+>@_Q4>-^3xm-AKtUsvj9gmH>v1XyI z?1I5y__4x9b@FE$$xjtaHN|8rrlrtb>lovgv9A;&_r|^?DTeK~ zwDdcfZ8?HB9*;K}jT)L0qgbq2;(g}MD&5^@icWSvJaay$;1BtYz5V0`833 ziCGf&tXxIK5?52yoq{hOHOm*0Ol;J5ciF(+lMF-<(KsRb%N;rIr-_TI=g+1SbCwc3 zqMuoH;Ng`@w?yC|5mR{))2NTMR?{FNPvbNZB*JtWW!?E=w4^|Jr|`7wc!sV$tDLGX zsM|%NmOavW<1!fEkork$yR-1?F+pTt@s%?SNrqTWHbH==$bmAD*|pf?L6dji2O8E? z)K~2Dy1j=il%F0;bSC+w&FRJ{l3)TviR~OKw8X)B6IPMy90OAB2}wr1eeL)f^SbEPLi*52c=cBQ{&m z+B_920jlKs&@8Gu8o~;ov|x>!)xPLvuxp3Pm=>xg=SZ3lD)NE z{A^wwqhD>RM|d5pxRdq4^0eFs&98^zM()tU4WQSwRY7f5lg4}%d*m@=Tm!d4V}z^! z+#hP!Os+xQxb9L#ln*zZbXE^1w>&?2^}BzOU?Des=Q#Ch_d(K{bFtsW(2R0-;o^Bp zF=!~B=WFd%V(F%|<|BBmD!!_Vx;^;SCJ<>0zpi``!am+;qTe!0DxMs1V5p^e>dT3* z)bH8LI&QgP7T>$4a))*Z^G)*+#!hJ&-MSWLF=pJX9#wp_TDs=*vU({m-R@qvy$hi+ zzglMPd$X01i^8z$;@AjT_#0(7+{uL?K7MoI<0CS_LTNK@*>~Ca6?%E|n5hdv&!w(f zWToP9{RkPf>@e0mFj)I>u*sx*)v-)wZM4xuYVx_0=$}oWMgubL`52KwDdR0c83YO@ zkc$318pOI6{#uneT-_sbYbq?m3GzuYkX87xvPUK?T9x_5d z2i=xFrJen~BGmBJ?%UE6E>AUttDk9r78q+wx1~QReM!2u`D^ZT4Upc`3Xe1;4b4|W z?-!#2y_$QIE-ogjYm)yOX?DJEC@`_;Sn+Z8M1bcCxwSs;Xo(Ib_`UU8>>`$IPgD(R z(}?eXOR=$rRJa_54b_V_Ewtd=zkAp(wY&-{zh^MTC?kPBXjW5hF^>y_DMfgq$66O+iJVrfkZP zS$vIB`t%>k?-)Q~l2i}sTmmt$lkLSnqRK3}8O?A0Ci%om_I(j zQXz|Zl&TAMK8ndVPl z`0aeEm-20U;cm#0Yzo@Qo33b2g=i&ro&9<_`WuB-&3YltOhY=oQ zYF`j8ja0SOl4u#kOWhQLninRuUCJvp_Pf+4Cz-$EDgFAdQeqt-iHI_Dsi1C3UW2xs z9buAU)pSmoabA@5C*@Tdp^o^r=U$58TPK-%u`Wl}3kVa3U>!CQIp!jBLyzVYkZ{sR zuq?HU*m~#&W4NkN_)1jwokFR&2bsbO50VKD5ouk80gVLt^saziEC{o#24MrSHYT>E z8CeNSLeerj*)RkF(te__G*P6RB84^13{DZbr8`$5e1!<WT`x z_>*g!>CGM?%9(v#%q}(73pI@KpP!`mYjnsYBucp(h(*C6h-ccqM&JflnRlnR95jTC zA(N+-Ba$>TDgTxA4h_Q^4a<0(emu@UF@u>=BBb--mh zh}al>Km48|Q=X;QeUC>>83E_5e#_%_L`N!1#u4J$;dzh#PyAaT zGADHQM|D&f4u|_EVjk!l{7;bW|2JZuus&k`UkjwdVF(xyDG!vpgk!Kk{d+hD^M4DK z2MGT?RQ^X)@UIn8Q5!3yBGu6UHB`PA2$dILd_1I|G@5rVs>MdvNJT~X{Ho{i9on%I z$p+dH2ZFz~W1bgEXuAkMUrHT@mitqe+r#VJ9qvjs{^iO4Ik;Zsg3^o7*96&sG1cc6 z)@B|Nb3W3h=*~w=iP&STcP$NdA=fL0CFX;p`TD}Iiyrs$b^B`h#Mg1GWP*PSEPm^) zLwiNl$?wWoIaj#PbU!0MQ~BD{7^D!+{c&oOZogfvv4(eMN%7|AnPS2AJK0i7JuiSZ z*j3RAC5}xCH?FIa8XtkTQa{)URq)d~#leR6;HQXLitH%0*c9uxo0d|R7-z;84cXFt z=R4)z3O5|pl+I;!y=xJw6`jlnoT!=XAjS(FGfZ1f$?UA$~X-j6`$VDqw$f&_)9t+%W(ghXuN8!-1H1 zphPQBG8Kddj9ZOEi~A1@31ozD3i$)ww*hm<;5g-70Ul@ohtsKB4Jhyr=g0*3sG&eV z3jPD~(Li@@BQfbt@P^;Gygq4{+H6P20$xs&IDRP4LHS#e?D;r_wxy8 zLh<(#8jSe+2?GY&4g8?sOvcYAH87Cq0>D7OmY4-vjsN2!I4Ln;)Q@Zx5Y*1x&70~T zaOe<}Z~_J9I1lf_6$&}$N5*CMWf*R8N=qCX# z)=&}+$m%)CVc{ME#ajclm;=4ssaA%%Py#rBMyF~5ohX38022JcoJ50PT?$9!dUb$; z(Cc*o{XZoD0vNEIXs{aKpMd2w@uK)UfPc&?=PTZi4vYl;OT!Mp!hV;5cMWho?&krF z+5;Hm&sBh$pQQTgxCeOo`8xdM1+}w30`{dJKmPLv4B$<4_4Saa`l{GiEBrd8=wC93 zbm#$|ezZdd`UVCt7)l2Q1B?=eK>{D(I|cy*oHh&w)F6gofFD3>_@5sfaQ_jNrq#A5#b{6`Ex zivZqnRQkaaAmFHlp%5s5ISPqZfuZDJFgb-^W;vKf zJq7|61`Yx^{e6KkXf#kq`55>o42#BLfD?psfqnmm0ncz?eSU|bId#7`z|??a^>;iq z1du28I}8iVH?WD;;UNL9^E(WV;dq4gFphDrhpBOPG3WY6XE-ov>ve%+QNT(3J01cC z$E>FXU>n8(a07}{ucyW00JGv;|HwrE>2T}Ei$rt0>+g5~jFaN?8!Zx8i4C+sN0jyB zMPg8ZC;pulg+y$?Lm`o{jd^Cf04QQ3KPA=fT*3SzT z@LRv=53xAP%A$_;2irq360=;%n$s-UjipCK@aQzK4gFd&T|+_ zUso3xg8>4A)rBGOItB&?SiBwG7{bZ|NtJPxU+rU&HD0iMf0z?By8!);+PXdtsyR#xBK0Q5hXo( Date: Fri, 3 Nov 2023 10:16:01 -0500 Subject: [PATCH 15/93] Update Linux CyberPatriot Checklist.txt --- Linux CyberPatriot Checklist.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Linux CyberPatriot Checklist.txt b/Linux CyberPatriot Checklist.txt index cffcfc8..ba00727 100644 --- a/Linux CyberPatriot Checklist.txt +++ b/Linux CyberPatriot Checklist.txt @@ -8,7 +8,7 @@ * Fix permissions * Delete hacking tools (like wireshark) * Set password requirements. (check below for detail) -* Install and Enable gufw (Terminal> “sudo apt install gufw”> type “gufw” and make status=ON and Incoming=Reject) +* Install and Enable gufw (Terminal> “sudo apt install ufw”> type “ufw” and make status=ON and Incoming=Reject) * Update software (Terminal> “sudo apt-update” > “sudo apt-upgrade”) * Change insecure password @@ -97,4 +97,4 @@ Disable guest accounts Tools and extras: * http://whois.domaintools.com/ * https://wiki.ubuntu.com/Security/features -* Check service configuration files for required services. Sometimes can get a point for finding a wrong setting in a config file for sql, apache, etc. \ No newline at end of file +* Check service configuration files for required services. Sometimes can get a point for finding a wrong setting in a config file for sql, apache, etc. From fa65bd2f11ae94fd76bc978e0de616d251f69bde Mon Sep 17 00:00:00 2001 From: NotMaxwell <142256213+NotMaxwell@users.noreply.github.com> Date: Mon, 13 Nov 2023 12:10:53 -0600 Subject: [PATCH 16/93] Update Windows CyberPatriot Checklist.txt --- Windows CyberPatriot Checklist.txt | 16 ++++++---------- 1 file changed, 6 insertions(+), 10 deletions(-) diff --git a/Windows CyberPatriot Checklist.txt b/Windows CyberPatriot Checklist.txt index 55b09a8..eaca322 100644 --- a/Windows CyberPatriot Checklist.txt +++ b/Windows CyberPatriot Checklist.txt @@ -38,12 +38,12 @@ Competition Checklist: * Remote Desktop * WWW Publishing Service * Deny the Following Ports in Control Panel. (Control Panel > System and Security > Windows Firewall > Advanced Settings > Inbound Rules or Outbound Rules > New Rule > Port > Next > TCP or UDP > Specific Local Ports > enter port number “like 80, 443, 20, etc.) > Next > Block the Connection > Next > Choose network location/s either public, domain, or private > Next > create a name > Finish) - * RDP - * SSH - * TelNet - * SNMP - * LDAP - * FTP + * RDP - 3389 + * SSH - 22 + * TelNet - 23 + * SNMP - 161/162 + * LDAP - 389 + * FTP - 21 (command)/20 (data) * Enable security features in Windows Security. (Settings > Update and Security > Windows Security > Protection Areas, enable as many as possible) * Run a quick scan on the machine with either Malware Removal Tool (Malwarebytes) or Windows Security. (either win+r > mrt > Quick Scan or Settings > Update and Security > Windows Security > Quick Scan) * Password security (win+r > gpedit.msc > Account Policy > Password Policy) OR @@ -103,7 +103,3 @@ Removing Malware (You will probably only need step 1) *Process Monitor(Gives detailed info about file system, registry, and thread activity)(https://learn.microsoft.com/en-us/sysinternals/downloads/procmon) *TCPView(lists all programs on the computer that are connected to a remote computer)(https://learn.microsoft.com/en-us/sysinternals/downloads/tcpview) - - -Notes: -idk lol \ No newline at end of file From 3eb9055beeceb049d1ce922fc84ffa561e6a183f Mon Sep 17 00:00:00 2001 From: NotMaxwell <142256213+NotMaxwell@users.noreply.github.com> Date: Tue, 14 Nov 2023 12:00:31 -0600 Subject: [PATCH 17/93] Update SCRIP_WIN_CP.ps1 --- Scripts/Windows/SCRIP_WIN_CP.ps1 | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Scripts/Windows/SCRIP_WIN_CP.ps1 b/Scripts/Windows/SCRIP_WIN_CP.ps1 index d308cef..80d820b 100644 --- a/Scripts/Windows/SCRIP_WIN_CP.ps1 +++ b/Scripts/Windows/SCRIP_WIN_CP.ps1 @@ -33,6 +33,7 @@ Auditpol /set /category:"DS Access" /success:enable /failure:enable auditpol /set /category:"Privilege Use" /success:enable /failure:enable auditpol /set /category:"Object Access" /success:enable /failure:enable auditpol /set /category:"System" /success:enable /failure:enable +auditpol /get /category* Set-ExecutionPolicy Bypass -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1')) @@ -49,4 +50,4 @@ New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name gpupdate /force Disable-localuser Guest -Disable-localuser Administrator \ No newline at end of file +Disable-localuser Administrator From 283404d5d9c3360bb52fb132d6d7080ad4996b7d Mon Sep 17 00:00:00 2001 From: SavageCabbage39 <100728985+SavageCabbage39@users.noreply.github.com> Date: Thu, 16 Nov 2023 12:17:51 -0600 Subject: [PATCH 18/93] Update SCRIP_WIN_CP.ps1 --- Scripts/Windows/SCRIP_WIN_CP.ps1 | 3 --- 1 file changed, 3 deletions(-) diff --git a/Scripts/Windows/SCRIP_WIN_CP.ps1 b/Scripts/Windows/SCRIP_WIN_CP.ps1 index 80d820b..804ea67 100644 --- a/Scripts/Windows/SCRIP_WIN_CP.ps1 +++ b/Scripts/Windows/SCRIP_WIN_CP.ps1 @@ -35,9 +35,6 @@ auditpol /set /category:"Object Access" /success:enable /failure:enable auditpol /set /category:"System" /success:enable /failure:enable auditpol /get /category* -Set-ExecutionPolicy Bypass -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1')) - -choco install malwarebytes -y Set-ExecutionPolicy RemoteSigned From e3a4aec8cf7574dfaeb40968f1da1daec75cf224 Mon Sep 17 00:00:00 2001 From: SavageCabbage39 <100728985+SavageCabbage39@users.noreply.github.com> Date: Mon, 27 Nov 2023 12:07:39 -0600 Subject: [PATCH 19/93] Add files via upload --- Important links and stuff.txt | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 Important links and stuff.txt diff --git a/Important links and stuff.txt b/Important links and stuff.txt new file mode 100644 index 0000000..96d0de4 --- /dev/null +++ b/Important links and stuff.txt @@ -0,0 +1,28 @@ +* Center for Internet Security - Provides numerous resources on Internet security and creates cybersecurity standards +* CNET - Offers the latest cybersecurity news and offers thoousands of open-source software programs for download +* Mandiant- Provides up-to-date information on the most dangerous threats in cyberspace +* Ninite - Hosts a program that can quickly update all of your software at once +* NOVA Labs - The Cybersecurity Lab is a game where players learn basic coding skills, how to spot phishing scams, and how online networks defend against attacks.​ +* SANS - Provides free and fee-based training and resources for cybersecurity professionals +* SourceForge - Hosts a wealth of open-source software, much of which can help keep an operating system secure from attacks +* Splunk- Offers a monitoring and reporting program that helps thwart attacks as they happen and provides insight into past attacks. Splunk is a CyberGold sponsor of CyberPatriot. +* SuperUser​​ - Uses the knowledge of computer experts around the world to answer cybersecurity questions +* TechRepublic - Contains a wide range of resources for technical professionals​ +* ​CyberSecurityEducation.org - Free collection of cyberseurity education and career resources + + + + +http://technet.microsoft.com/en-us/library/default.aspx + + +http://www.bleepingcomputer.com/tutorials/tutorial74.html + + +http://windows.microsoft.com/en-us/windows7/products/features/windows-firewall + + +http://www.windowsnetworking.com/ + + +http://technet.microsoft.com/en-us/sysinternals/bb545021.aspx \ No newline at end of file From c28cf0c17f8a596d7302ceceff8848d8baf7fe4a Mon Sep 17 00:00:00 2001 From: SavageCabbage39 <100728985+SavageCabbage39@users.noreply.github.com> Date: Mon, 27 Nov 2023 19:55:48 -0600 Subject: [PATCH 20/93] Update Important links and stuff.txt Bunch of useful tools and stuffs --- Important links and stuff.txt | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/Important links and stuff.txt b/Important links and stuff.txt index 96d0de4..c811ef7 100644 --- a/Important links and stuff.txt +++ b/Important links and stuff.txt @@ -1,4 +1,4 @@ -* Center for Internet Security - Provides numerous resources on Internet security and creates cybersecurity standards +* Center for Internet Security - Provides numerous resources on Internet security and creates cybersecurity standards * CNET - Offers the latest cybersecurity news and offers thoousands of open-source software programs for download * Mandiant- Provides up-to-date information on the most dangerous threats in cyberspace * Ninite - Hosts a program that can quickly update all of your software at once @@ -9,9 +9,10 @@ * SuperUser​​ - Uses the knowledge of computer experts around the world to answer cybersecurity questions * TechRepublic - Contains a wide range of resources for technical professionals​ * ​CyberSecurityEducation.org - Free collection of cyberseurity education and career resources +* Meld(http://meldmerge.org/)- a visually based diffing and merging tool for files and directories that works on both Linux and Windows. - +https://akshayrohatgi.com/blog/posts/How-To-Win-CyberPatriot/ http://technet.microsoft.com/en-us/library/default.aspx @@ -25,4 +26,7 @@ http://windows.microsoft.com/en-us/windows7/products/features/windows-firewall http://www.windowsnetworking.com/ -http://technet.microsoft.com/en-us/sysinternals/bb545021.aspx \ No newline at end of file +http://technet.microsoft.com/en-us/sysinternals/bb545021.aspx + +https://www.youtube.com/playlist?list=PLcn9NsWbb8s4wQrX0Qi5G4kRifQHxCV9- + From 6a1cf89b66a96c651b76755007a6e2f4f085aa9b Mon Sep 17 00:00:00 2001 From: Justin Wright Date: Thu, 30 Nov 2023 00:02:06 -0600 Subject: [PATCH 21/93] Create CODE_OF_CONDUCT.md self explanatory --- CODE_OF_CONDUCT.md | 128 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 128 insertions(+) create mode 100644 CODE_OF_CONDUCT.md diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..cae59b3 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,128 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic status, +nationality, personal appearance, race, religion, or sexual identity +and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment for our +community include: + +* Demonstrating empathy and kindness toward other people +* Being respectful of differing opinions, viewpoints, and experiences +* Giving and gracefully accepting constructive feedback +* Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +* Focusing on what is best not just for us as individuals, but for the + overall community + +Examples of unacceptable behavior include: + +* The use of sexualized language or imagery, and sexual attention or + advances of any kind +* Trolling, insulting or derogatory comments, and personal or political attacks +* Public or private harassment +* Publishing others' private information, such as a physical or email + address, without their explicit permission +* Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official e-mail address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement at +justin.wright@ascte.org. +All complaints will be reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact**: Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence**: A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact**: A violation through a single incident or series +of actions. + +**Consequence**: A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or +permanent ban. + +### 3. Temporary Ban + +**Community Impact**: A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence**: A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact**: Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence**: A permanent ban from any sort of public interaction within +the community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.0, available at +https://www.contributor-covenant.org/version/2/0/code_of_conduct.html. + +Community Impact Guidelines were inspired by [Mozilla's code of conduct +enforcement ladder](https://github.com/mozilla/diversity). + +[homepage]: https://www.contributor-covenant.org + +For answers to common questions about this code of conduct, see the FAQ at +https://www.contributor-covenant.org/faq. Translations are available at +https://www.contributor-covenant.org/translations. From c839103070e7d180d1c43b6c552c2fa4def5164f Mon Sep 17 00:00:00 2001 From: Justin Wright Date: Thu, 30 Nov 2023 00:04:31 -0600 Subject: [PATCH 22/93] Create LICENSE --- LICENSE | 674 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 674 insertions(+) create mode 100644 LICENSE diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..f288702 --- /dev/null +++ b/LICENSE @@ -0,0 +1,674 @@ + GNU GENERAL PUBLIC LICENSE + Version 3, 29 June 2007 + + Copyright (C) 2007 Free Software Foundation, Inc. + Everyone is permitted to copy and distribute verbatim copies + of this license document, but changing it is not allowed. + + Preamble + + The GNU General Public License is a free, copyleft license for +software and other kinds of works. + + The licenses for most software and other practical works are designed +to take away your freedom to share and change the works. By contrast, +the GNU General Public License is intended to guarantee your freedom to +share and change all versions of a program--to make sure it remains free +software for all its users. We, the Free Software Foundation, use the +GNU General Public License for most of our software; it applies also to +any other work released this way by its authors. You can apply it to +your programs, too. + + When we speak of free software, we are referring to freedom, not +price. Our General Public Licenses are designed to make sure that you +have the freedom to distribute copies of free software (and charge for +them if you wish), that you receive source code or can get it if you +want it, that you can change the software or use pieces of it in new +free programs, and that you know you can do these things. + + To protect your rights, we need to prevent others from denying you +these rights or asking you to surrender the rights. Therefore, you have +certain responsibilities if you distribute copies of the software, or if +you modify it: responsibilities to respect the freedom of others. + + For example, if you distribute copies of such a program, whether +gratis or for a fee, you must pass on to the recipients the same +freedoms that you received. You must make sure that they, too, receive +or can get the source code. And you must show them these terms so they +know their rights. + + Developers that use the GNU GPL protect your rights with two steps: +(1) assert copyright on the software, and (2) offer you this License +giving you legal permission to copy, distribute and/or modify it. + + For the developers' and authors' protection, the GPL clearly explains +that there is no warranty for this free software. For both users' and +authors' sake, the GPL requires that modified versions be marked as +changed, so that their problems will not be attributed erroneously to +authors of previous versions. + + Some devices are designed to deny users access to install or run +modified versions of the software inside them, although the manufacturer +can do so. This is fundamentally incompatible with the aim of +protecting users' freedom to change the software. The systematic +pattern of such abuse occurs in the area of products for individuals to +use, which is precisely where it is most unacceptable. Therefore, we +have designed this version of the GPL to prohibit the practice for those +products. If such problems arise substantially in other domains, we +stand ready to extend this provision to those domains in future versions +of the GPL, as needed to protect the freedom of users. + + Finally, every program is threatened constantly by software patents. +States should not allow patents to restrict development and use of +software on general-purpose computers, but in those that do, we wish to +avoid the special danger that patents applied to a free program could +make it effectively proprietary. To prevent this, the GPL assures that +patents cannot be used to render the program non-free. + + The precise terms and conditions for copying, distribution and +modification follow. + + TERMS AND CONDITIONS + + 0. Definitions. + + "This License" refers to version 3 of the GNU General Public License. + + "Copyright" also means copyright-like laws that apply to other kinds of +works, such as semiconductor masks. + + "The Program" refers to any copyrightable work licensed under this +License. Each licensee is addressed as "you". "Licensees" and +"recipients" may be individuals or organizations. + + To "modify" a work means to copy from or adapt all or part of the work +in a fashion requiring copyright permission, other than the making of an +exact copy. The resulting work is called a "modified version" of the +earlier work or a work "based on" the earlier work. + + A "covered work" means either the unmodified Program or a work based +on the Program. + + To "propagate" a work means to do anything with it that, without +permission, would make you directly or secondarily liable for +infringement under applicable copyright law, except executing it on a +computer or modifying a private copy. Propagation includes copying, +distribution (with or without modification), making available to the +public, and in some countries other activities as well. + + To "convey" a work means any kind of propagation that enables other +parties to make or receive copies. Mere interaction with a user through +a computer network, with no transfer of a copy, is not conveying. + + An interactive user interface displays "Appropriate Legal Notices" +to the extent that it includes a convenient and prominently visible +feature that (1) displays an appropriate copyright notice, and (2) +tells the user that there is no warranty for the work (except to the +extent that warranties are provided), that licensees may convey the +work under this License, and how to view a copy of this License. If +the interface presents a list of user commands or options, such as a +menu, a prominent item in the list meets this criterion. + + 1. Source Code. + + The "source code" for a work means the preferred form of the work +for making modifications to it. "Object code" means any non-source +form of a work. + + A "Standard Interface" means an interface that either is an official +standard defined by a recognized standards body, or, in the case of +interfaces specified for a particular programming language, one that +is widely used among developers working in that language. + + The "System Libraries" of an executable work include anything, other +than the work as a whole, that (a) is included in the normal form of +packaging a Major Component, but which is not part of that Major +Component, and (b) serves only to enable use of the work with that +Major Component, or to implement a Standard Interface for which an +implementation is available to the public in source code form. A +"Major Component", in this context, means a major essential component +(kernel, window system, and so on) of the specific operating system +(if any) on which the executable work runs, or a compiler used to +produce the work, or an object code interpreter used to run it. + + The "Corresponding Source" for a work in object code form means all +the source code needed to generate, install, and (for an executable +work) run the object code and to modify the work, including scripts to +control those activities. However, it does not include the work's +System Libraries, or general-purpose tools or generally available free +programs which are used unmodified in performing those activities but +which are not part of the work. For example, Corresponding Source +includes interface definition files associated with source files for +the work, and the source code for shared libraries and dynamically +linked subprograms that the work is specifically designed to require, +such as by intimate data communication or control flow between those +subprograms and other parts of the work. + + The Corresponding Source need not include anything that users +can regenerate automatically from other parts of the Corresponding +Source. + + The Corresponding Source for a work in source code form is that +same work. + + 2. Basic Permissions. + + All rights granted under this License are granted for the term of +copyright on the Program, and are irrevocable provided the stated +conditions are met. This License explicitly affirms your unlimited +permission to run the unmodified Program. The output from running a +covered work is covered by this License only if the output, given its +content, constitutes a covered work. This License acknowledges your +rights of fair use or other equivalent, as provided by copyright law. + + You may make, run and propagate covered works that you do not +convey, without conditions so long as your license otherwise remains +in force. You may convey covered works to others for the sole purpose +of having them make modifications exclusively for you, or provide you +with facilities for running those works, provided that you comply with +the terms of this License in conveying all material for which you do +not control copyright. Those thus making or running the covered works +for you must do so exclusively on your behalf, under your direction +and control, on terms that prohibit them from making any copies of +your copyrighted material outside their relationship with you. + + Conveying under any other circumstances is permitted solely under +the conditions stated below. Sublicensing is not allowed; section 10 +makes it unnecessary. + + 3. Protecting Users' Legal Rights From Anti-Circumvention Law. + + No covered work shall be deemed part of an effective technological +measure under any applicable law fulfilling obligations under article +11 of the WIPO copyright treaty adopted on 20 December 1996, or +similar laws prohibiting or restricting circumvention of such +measures. + + When you convey a covered work, you waive any legal power to forbid +circumvention of technological measures to the extent such circumvention +is effected by exercising rights under this License with respect to +the covered work, and you disclaim any intention to limit operation or +modification of the work as a means of enforcing, against the work's +users, your or third parties' legal rights to forbid circumvention of +technological measures. + + 4. Conveying Verbatim Copies. + + You may convey verbatim copies of the Program's source code as you +receive it, in any medium, provided that you conspicuously and +appropriately publish on each copy an appropriate copyright notice; +keep intact all notices stating that this License and any +non-permissive terms added in accord with section 7 apply to the code; +keep intact all notices of the absence of any warranty; and give all +recipients a copy of this License along with the Program. + + You may charge any price or no price for each copy that you convey, +and you may offer support or warranty protection for a fee. + + 5. Conveying Modified Source Versions. + + You may convey a work based on the Program, or the modifications to +produce it from the Program, in the form of source code under the +terms of section 4, provided that you also meet all of these conditions: + + a) The work must carry prominent notices stating that you modified + it, and giving a relevant date. + + b) The work must carry prominent notices stating that it is + released under this License and any conditions added under section + 7. This requirement modifies the requirement in section 4 to + "keep intact all notices". + + c) You must license the entire work, as a whole, under this + License to anyone who comes into possession of a copy. This + License will therefore apply, along with any applicable section 7 + additional terms, to the whole of the work, and all its parts, + regardless of how they are packaged. This License gives no + permission to license the work in any other way, but it does not + invalidate such permission if you have separately received it. + + d) If the work has interactive user interfaces, each must display + Appropriate Legal Notices; however, if the Program has interactive + interfaces that do not display Appropriate Legal Notices, your + work need not make them do so. + + A compilation of a covered work with other separate and independent +works, which are not by their nature extensions of the covered work, +and which are not combined with it such as to form a larger program, +in or on a volume of a storage or distribution medium, is called an +"aggregate" if the compilation and its resulting copyright are not +used to limit the access or legal rights of the compilation's users +beyond what the individual works permit. Inclusion of a covered work +in an aggregate does not cause this License to apply to the other +parts of the aggregate. + + 6. Conveying Non-Source Forms. + + You may convey a covered work in object code form under the terms +of sections 4 and 5, provided that you also convey the +machine-readable Corresponding Source under the terms of this License, +in one of these ways: + + a) Convey the object code in, or embodied in, a physical product + (including a physical distribution medium), accompanied by the + Corresponding Source fixed on a durable physical medium + customarily used for software interchange. + + b) Convey the object code in, or embodied in, a physical product + (including a physical distribution medium), accompanied by a + written offer, valid for at least three years and valid for as + long as you offer spare parts or customer support for that product + model, to give anyone who possesses the object code either (1) a + copy of the Corresponding Source for all the software in the + product that is covered by this License, on a durable physical + medium customarily used for software interchange, for a price no + more than your reasonable cost of physically performing this + conveying of source, or (2) access to copy the + Corresponding Source from a network server at no charge. + + c) Convey individual copies of the object code with a copy of the + written offer to provide the Corresponding Source. This + alternative is allowed only occasionally and noncommercially, and + only if you received the object code with such an offer, in accord + with subsection 6b. + + d) Convey the object code by offering access from a designated + place (gratis or for a charge), and offer equivalent access to the + Corresponding Source in the same way through the same place at no + further charge. You need not require recipients to copy the + Corresponding Source along with the object code. If the place to + copy the object code is a network server, the Corresponding Source + may be on a different server (operated by you or a third party) + that supports equivalent copying facilities, provided you maintain + clear directions next to the object code saying where to find the + Corresponding Source. Regardless of what server hosts the + Corresponding Source, you remain obligated to ensure that it is + available for as long as needed to satisfy these requirements. + + e) Convey the object code using peer-to-peer transmission, provided + you inform other peers where the object code and Corresponding + Source of the work are being offered to the general public at no + charge under subsection 6d. + + A separable portion of the object code, whose source code is excluded +from the Corresponding Source as a System Library, need not be +included in conveying the object code work. + + A "User Product" is either (1) a "consumer product", which means any +tangible personal property which is normally used for personal, family, +or household purposes, or (2) anything designed or sold for incorporation +into a dwelling. In determining whether a product is a consumer product, +doubtful cases shall be resolved in favor of coverage. For a particular +product received by a particular user, "normally used" refers to a +typical or common use of that class of product, regardless of the status +of the particular user or of the way in which the particular user +actually uses, or expects or is expected to use, the product. A product +is a consumer product regardless of whether the product has substantial +commercial, industrial or non-consumer uses, unless such uses represent +the only significant mode of use of the product. + + "Installation Information" for a User Product means any methods, +procedures, authorization keys, or other information required to install +and execute modified versions of a covered work in that User Product from +a modified version of its Corresponding Source. The information must +suffice to ensure that the continued functioning of the modified object +code is in no case prevented or interfered with solely because +modification has been made. + + If you convey an object code work under this section in, or with, or +specifically for use in, a User Product, and the conveying occurs as +part of a transaction in which the right of possession and use of the +User Product is transferred to the recipient in perpetuity or for a +fixed term (regardless of how the transaction is characterized), the +Corresponding Source conveyed under this section must be accompanied +by the Installation Information. But this requirement does not apply +if neither you nor any third party retains the ability to install +modified object code on the User Product (for example, the work has +been installed in ROM). + + The requirement to provide Installation Information does not include a +requirement to continue to provide support service, warranty, or updates +for a work that has been modified or installed by the recipient, or for +the User Product in which it has been modified or installed. Access to a +network may be denied when the modification itself materially and +adversely affects the operation of the network or violates the rules and +protocols for communication across the network. + + Corresponding Source conveyed, and Installation Information provided, +in accord with this section must be in a format that is publicly +documented (and with an implementation available to the public in +source code form), and must require no special password or key for +unpacking, reading or copying. + + 7. Additional Terms. + + "Additional permissions" are terms that supplement the terms of this +License by making exceptions from one or more of its conditions. +Additional permissions that are applicable to the entire Program shall +be treated as though they were included in this License, to the extent +that they are valid under applicable law. If additional permissions +apply only to part of the Program, that part may be used separately +under those permissions, but the entire Program remains governed by +this License without regard to the additional permissions. + + When you convey a copy of a covered work, you may at your option +remove any additional permissions from that copy, or from any part of +it. (Additional permissions may be written to require their own +removal in certain cases when you modify the work.) You may place +additional permissions on material, added by you to a covered work, +for which you have or can give appropriate copyright permission. + + Notwithstanding any other provision of this License, for material you +add to a covered work, you may (if authorized by the copyright holders of +that material) supplement the terms of this License with terms: + + a) Disclaiming warranty or limiting liability differently from the + terms of sections 15 and 16 of this License; or + + b) Requiring preservation of specified reasonable legal notices or + author attributions in that material or in the Appropriate Legal + Notices displayed by works containing it; or + + c) Prohibiting misrepresentation of the origin of that material, or + requiring that modified versions of such material be marked in + reasonable ways as different from the original version; or + + d) Limiting the use for publicity purposes of names of licensors or + authors of the material; or + + e) Declining to grant rights under trademark law for use of some + trade names, trademarks, or service marks; or + + f) Requiring indemnification of licensors and authors of that + material by anyone who conveys the material (or modified versions of + it) with contractual assumptions of liability to the recipient, for + any liability that these contractual assumptions directly impose on + those licensors and authors. + + All other non-permissive additional terms are considered "further +restrictions" within the meaning of section 10. If the Program as you +received it, or any part of it, contains a notice stating that it is +governed by this License along with a term that is a further +restriction, you may remove that term. If a license document contains +a further restriction but permits relicensing or conveying under this +License, you may add to a covered work material governed by the terms +of that license document, provided that the further restriction does +not survive such relicensing or conveying. + + If you add terms to a covered work in accord with this section, you +must place, in the relevant source files, a statement of the +additional terms that apply to those files, or a notice indicating +where to find the applicable terms. + + Additional terms, permissive or non-permissive, may be stated in the +form of a separately written license, or stated as exceptions; +the above requirements apply either way. + + 8. Termination. + + You may not propagate or modify a covered work except as expressly +provided under this License. Any attempt otherwise to propagate or +modify it is void, and will automatically terminate your rights under +this License (including any patent licenses granted under the third +paragraph of section 11). + + However, if you cease all violation of this License, then your +license from a particular copyright holder is reinstated (a) +provisionally, unless and until the copyright holder explicitly and +finally terminates your license, and (b) permanently, if the copyright +holder fails to notify you of the violation by some reasonable means +prior to 60 days after the cessation. + + Moreover, your license from a particular copyright holder is +reinstated permanently if the copyright holder notifies you of the +violation by some reasonable means, this is the first time you have +received notice of violation of this License (for any work) from that +copyright holder, and you cure the violation prior to 30 days after +your receipt of the notice. + + Termination of your rights under this section does not terminate the +licenses of parties who have received copies or rights from you under +this License. If your rights have been terminated and not permanently +reinstated, you do not qualify to receive new licenses for the same +material under section 10. + + 9. Acceptance Not Required for Having Copies. + + You are not required to accept this License in order to receive or +run a copy of the Program. Ancillary propagation of a covered work +occurring solely as a consequence of using peer-to-peer transmission +to receive a copy likewise does not require acceptance. However, +nothing other than this License grants you permission to propagate or +modify any covered work. These actions infringe copyright if you do +not accept this License. Therefore, by modifying or propagating a +covered work, you indicate your acceptance of this License to do so. + + 10. Automatic Licensing of Downstream Recipients. + + Each time you convey a covered work, the recipient automatically +receives a license from the original licensors, to run, modify and +propagate that work, subject to this License. You are not responsible +for enforcing compliance by third parties with this License. + + An "entity transaction" is a transaction transferring control of an +organization, or substantially all assets of one, or subdividing an +organization, or merging organizations. If propagation of a covered +work results from an entity transaction, each party to that +transaction who receives a copy of the work also receives whatever +licenses to the work the party's predecessor in interest had or could +give under the previous paragraph, plus a right to possession of the +Corresponding Source of the work from the predecessor in interest, if +the predecessor has it or can get it with reasonable efforts. + + You may not impose any further restrictions on the exercise of the +rights granted or affirmed under this License. For example, you may +not impose a license fee, royalty, or other charge for exercise of +rights granted under this License, and you may not initiate litigation +(including a cross-claim or counterclaim in a lawsuit) alleging that +any patent claim is infringed by making, using, selling, offering for +sale, or importing the Program or any portion of it. + + 11. Patents. + + A "contributor" is a copyright holder who authorizes use under this +License of the Program or a work on which the Program is based. The +work thus licensed is called the contributor's "contributor version". + + A contributor's "essential patent claims" are all patent claims +owned or controlled by the contributor, whether already acquired or +hereafter acquired, that would be infringed by some manner, permitted +by this License, of making, using, or selling its contributor version, +but do not include claims that would be infringed only as a +consequence of further modification of the contributor version. For +purposes of this definition, "control" includes the right to grant +patent sublicenses in a manner consistent with the requirements of +this License. + + Each contributor grants you a non-exclusive, worldwide, royalty-free +patent license under the contributor's essential patent claims, to +make, use, sell, offer for sale, import and otherwise run, modify and +propagate the contents of its contributor version. + + In the following three paragraphs, a "patent license" is any express +agreement or commitment, however denominated, not to enforce a patent +(such as an express permission to practice a patent or covenant not to +sue for patent infringement). To "grant" such a patent license to a +party means to make such an agreement or commitment not to enforce a +patent against the party. + + If you convey a covered work, knowingly relying on a patent license, +and the Corresponding Source of the work is not available for anyone +to copy, free of charge and under the terms of this License, through a +publicly available network server or other readily accessible means, +then you must either (1) cause the Corresponding Source to be so +available, or (2) arrange to deprive yourself of the benefit of the +patent license for this particular work, or (3) arrange, in a manner +consistent with the requirements of this License, to extend the patent +license to downstream recipients. "Knowingly relying" means you have +actual knowledge that, but for the patent license, your conveying the +covered work in a country, or your recipient's use of the covered work +in a country, would infringe one or more identifiable patents in that +country that you have reason to believe are valid. + + If, pursuant to or in connection with a single transaction or +arrangement, you convey, or propagate by procuring conveyance of, a +covered work, and grant a patent license to some of the parties +receiving the covered work authorizing them to use, propagate, modify +or convey a specific copy of the covered work, then the patent license +you grant is automatically extended to all recipients of the covered +work and works based on it. + + A patent license is "discriminatory" if it does not include within +the scope of its coverage, prohibits the exercise of, or is +conditioned on the non-exercise of one or more of the rights that are +specifically granted under this License. You may not convey a covered +work if you are a party to an arrangement with a third party that is +in the business of distributing software, under which you make payment +to the third party based on the extent of your activity of conveying +the work, and under which the third party grants, to any of the +parties who would receive the covered work from you, a discriminatory +patent license (a) in connection with copies of the covered work +conveyed by you (or copies made from those copies), or (b) primarily +for and in connection with specific products or compilations that +contain the covered work, unless you entered into that arrangement, +or that patent license was granted, prior to 28 March 2007. + + Nothing in this License shall be construed as excluding or limiting +any implied license or other defenses to infringement that may +otherwise be available to you under applicable patent law. + + 12. No Surrender of Others' Freedom. + + If conditions are imposed on you (whether by court order, agreement or +otherwise) that contradict the conditions of this License, they do not +excuse you from the conditions of this License. If you cannot convey a +covered work so as to satisfy simultaneously your obligations under this +License and any other pertinent obligations, then as a consequence you may +not convey it at all. For example, if you agree to terms that obligate you +to collect a royalty for further conveying from those to whom you convey +the Program, the only way you could satisfy both those terms and this +License would be to refrain entirely from conveying the Program. + + 13. Use with the GNU Affero General Public License. + + Notwithstanding any other provision of this License, you have +permission to link or combine any covered work with a work licensed +under version 3 of the GNU Affero General Public License into a single +combined work, and to convey the resulting work. The terms of this +License will continue to apply to the part which is the covered work, +but the special requirements of the GNU Affero General Public License, +section 13, concerning interaction through a network will apply to the +combination as such. + + 14. Revised Versions of this License. + + The Free Software Foundation may publish revised and/or new versions of +the GNU General Public License from time to time. Such new versions will +be similar in spirit to the present version, but may differ in detail to +address new problems or concerns. + + Each version is given a distinguishing version number. If the +Program specifies that a certain numbered version of the GNU General +Public License "or any later version" applies to it, you have the +option of following the terms and conditions either of that numbered +version or of any later version published by the Free Software +Foundation. If the Program does not specify a version number of the +GNU General Public License, you may choose any version ever published +by the Free Software Foundation. + + If the Program specifies that a proxy can decide which future +versions of the GNU General Public License can be used, that proxy's +public statement of acceptance of a version permanently authorizes you +to choose that version for the Program. + + Later license versions may give you additional or different +permissions. However, no additional obligations are imposed on any +author or copyright holder as a result of your choosing to follow a +later version. + + 15. Disclaimer of Warranty. + + THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY +APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT +HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY +OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, +THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM +IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF +ALL NECESSARY SERVICING, REPAIR OR CORRECTION. + + 16. Limitation of Liability. + + IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING +WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS +THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY +GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE +USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF +DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD +PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), +EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF +SUCH DAMAGES. + + 17. Interpretation of Sections 15 and 16. + + If the disclaimer of warranty and limitation of liability provided +above cannot be given local legal effect according to their terms, +reviewing courts shall apply local law that most closely approximates +an absolute waiver of all civil liability in connection with the +Program, unless a warranty or assumption of liability accompanies a +copy of the Program in return for a fee. + + END OF TERMS AND CONDITIONS + + How to Apply These Terms to Your New Programs + + If you develop a new program, and you want it to be of the greatest +possible use to the public, the best way to achieve this is to make it +free software which everyone can redistribute and change under these terms. + + To do so, attach the following notices to the program. It is safest +to attach them to the start of each source file to most effectively +state the exclusion of warranty; and each file should have at least +the "copyright" line and a pointer to where the full notice is found. + + + Copyright (C) + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU General Public License as published by + the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + + You should have received a copy of the GNU General Public License + along with this program. If not, see . + +Also add information on how to contact you by electronic and paper mail. + + If the program does terminal interaction, make it output a short +notice like this when it starts in an interactive mode: + + Copyright (C) + This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'. + This is free software, and you are welcome to redistribute it + under certain conditions; type `show c' for details. + +The hypothetical commands `show w' and `show c' should show the appropriate +parts of the General Public License. Of course, your program's commands +might be different; for a GUI interface, you would use an "about box". + + You should also get your employer (if you work as a programmer) or school, +if any, to sign a "copyright disclaimer" for the program, if necessary. +For more information on this, and how to apply and follow the GNU GPL, see +. + + The GNU General Public License does not permit incorporating your program +into proprietary programs. If your program is a subroutine library, you +may consider it more useful to permit linking proprietary applications with +the library. If this is what you want to do, use the GNU Lesser General +Public License instead of this License. But first, please read +. From 53ccd1ac878d89a55d37fd90a599a33bc63c6640 Mon Sep 17 00:00:00 2001 From: Justin Wright Date: Thu, 30 Nov 2023 00:08:53 -0600 Subject: [PATCH 23/93] Create SECURITY.md --- SECURITY.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..3e15e85 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,16 @@ +# Security Policy + +## Supported Versions + +SOFTWARE PROVIDED WITH NO WARRANTY +EXTREMELY EXPERIMENTAL, CAN AND PROBABLY WILL DAMAGE YOUR COMPUTER IF USED INCORRECTLY + +| Version | Supported | +| ------- | ------------------ | +| 5.1.x | :x: | +| 5.0.x | :x: | +| 4.0.x | :x: | +| < 4.0 | :x: | + +## Reporting a Vulnerability + submit an issue From 5607b94efb3ae0e1fcb5a4a187fbb58c2b7d47c3 Mon Sep 17 00:00:00 2001 From: Justin Wright Date: Thu, 30 Nov 2023 00:10:16 -0600 Subject: [PATCH 24/93] Update issue templates --- .github/ISSUE_TEMPLATE/bug_report.md | 38 +++++++++++++++++++++++ .github/ISSUE_TEMPLATE/feature_request.md | 20 ++++++++++++ 2 files changed, 58 insertions(+) create mode 100644 .github/ISSUE_TEMPLATE/bug_report.md create mode 100644 .github/ISSUE_TEMPLATE/feature_request.md diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 0000000..dd84ea7 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,38 @@ +--- +name: Bug report +about: Create a report to help us improve +title: '' +labels: '' +assignees: '' + +--- + +**Describe the bug** +A clear and concise description of what the bug is. + +**To Reproduce** +Steps to reproduce the behavior: +1. Go to '...' +2. Click on '....' +3. Scroll down to '....' +4. See error + +**Expected behavior** +A clear and concise description of what you expected to happen. + +**Screenshots** +If applicable, add screenshots to help explain your problem. + +**Desktop (please complete the following information):** + - OS: [e.g. iOS] + - Browser [e.g. chrome, safari] + - Version [e.g. 22] + +**Smartphone (please complete the following information):** + - Device: [e.g. iPhone6] + - OS: [e.g. iOS8.1] + - Browser [e.g. stock browser, safari] + - Version [e.g. 22] + +**Additional context** +Add any other context about the problem here. diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 0000000..bbcbbe7 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,20 @@ +--- +name: Feature request +about: Suggest an idea for this project +title: '' +labels: '' +assignees: '' + +--- + +**Is your feature request related to a problem? Please describe.** +A clear and concise description of what the problem is. Ex. I'm always frustrated when [...] + +**Describe the solution you'd like** +A clear and concise description of what you want to happen. + +**Describe alternatives you've considered** +A clear and concise description of any alternative solutions or features you've considered. + +**Additional context** +Add any other context or screenshots about the feature request here. From e28c497edb7905b2eb5485e1931ab2de8257ab36 Mon Sep 17 00:00:00 2001 From: Justin Wright Date: Thu, 30 Nov 2023 00:11:32 -0600 Subject: [PATCH 25/93] Create CONTRIBUTING.md --- CONTRIBUTING.md | 1 + 1 file changed, 1 insertion(+) create mode 100644 CONTRIBUTING.md diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..b11a426 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1 @@ +Feel free to improve on any scripts. Feedback is very welcome. From c3811fb863a08c65bdbc7e719e59a738190f2121 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 30 Nov 2023 11:45:14 -0600 Subject: [PATCH 26/93] Update Linux CyberPatriot Checklist.txt --- Linux CyberPatriot Checklist.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Linux CyberPatriot Checklist.txt b/Linux CyberPatriot Checklist.txt index ba00727..d2d62e6 100644 --- a/Linux CyberPatriot Checklist.txt +++ b/Linux CyberPatriot Checklist.txt @@ -16,7 +16,7 @@ Security tools to install (“sudo apt install [PROGRAM NAME]”) * Clamav (open it with “clamscan” after install)(virus removal tool) -* Gufw(firewall) +* ufw(firewall) * Openssh-server(ssh service) * libpam-cracklib(creates better password policies) * Bum (Boot Up Manager) (Use “sudo bum” to run) From 1efd362769f78534876714b1dfeb40e9d10af8d9 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 30 Nov 2023 19:51:55 -0600 Subject: [PATCH 27/93] Add files via upload --- Scripts/Linux/script.py | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 Scripts/Linux/script.py diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py new file mode 100644 index 0000000..36d26a2 --- /dev/null +++ b/Scripts/Linux/script.py @@ -0,0 +1,15 @@ +#script + +from subprocess import run +#disable guest +run(["sudo", "usermod", "--expiredate", "1", "guest"]) + +# update system and apps +run(["sudo", "apt", "update"]) +run(["sudo", "apt", "upgrade"]) +run(["sudo", "apt", "full-upgrade") +run(["sudo", "apt", "autoremove") + +#Install/enable UFW +run(["sudo", "apt", "get", "ufw"]) +run(["sudo", "enable", "ufw"]) From 23246bc8bbc420995a09f12a717e18a728b963f7 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 30 Nov 2023 19:54:36 -0600 Subject: [PATCH 28/93] GideoNewLinuxScriptWIP.py --- Scripts/Linux/script.py | 52 +++++++++++++++++++++++++++++++++++++---- 1 file changed, 47 insertions(+), 5 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 36d26a2..e24a1ea 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -1,15 +1,57 @@ #script -from subprocess import run +import subprocess #disable guest run(["sudo", "usermod", "--expiredate", "1", "guest"]) # update system and apps run(["sudo", "apt", "update"]) run(["sudo", "apt", "upgrade"]) -run(["sudo", "apt", "full-upgrade") -run(["sudo", "apt", "autoremove") +run(["sudo", "apt", "full-upgrade"]) +run(["sudo", "apt", "autoremove"]) -#Install/enable UFW -run(["sudo", "apt", "get", "ufw"]) +#Install Security tools +run(["sudo", "apt-get", "ufw"]) run(["sudo", "enable", "ufw"]) +run(["sudo", "apt-get", "Clamav"]) +run(["sudo", "apt-get", "Openssh-server"]) +run(["sudo", "apt-get", "libpam-cracklib"]) +run(["sudo", "apt-get", "bum"]) +#disable ctrl+alt+delete +run(["sudo", "sed", "-i", "/^exec uim-systray/a Exec=/bin/false", "/etc/lightdm/lightdm.conf",]) + +# Password complexity requirement. +run(["sudo", "sed", "-i", f"s/^PASS_COMPLEXITY.*/PASS_COMPLEXITY {complexity}/", "/etc/login.defs"]) + +#remove wireshark if its installed (User is responsible for figuring out if wireshark exists.) +WireRemove = input("Does wireshark exist and need to be deleted?: ") +if (WireRemove == "yes" or WireRemove == "Yes"): + run(["sudo", "apt-get", "remove", "--purge", "wireshark"]) + run(["sudo", "apt-get", "autoremove"]) + +#update firefox +FoxUpdate = input("Does FireFox need updated?: ") +if (FoxUpdate == "yes" or FoxUpdate == "Yes"): + run(["sudo", "apt", "install", "firefox"]) +#enable SSH +sshEnable = input("Does ssh need enabled?: ") +if (sshEnable == "yes" or sshEnable == "Yes"): + run(["sudo", "systemctl", "enable", "ssh"]) + run(["sudo", "systemctl", "start", "ssh"]) +#change minimum password age +#change min password length +check_command = "grep -q 'minlen=' /etc/pam.d/common-password && echo 'exists' || echo 'not exists'" +check_process = subprocess.run(check_command, shell=True, capture_output=True, text=True) +check_result = check_process.stdout.strip() + +try: +if check_result == 'exists': + command = f"sudo sed -i 's/\\bminlen=[0-9]\\+\\b/minlen={length}/' /etc/pam.d/common-password" +else: + command = f"sudo sed -i '/pam_unix.so/ s/$/ minlen={length}/' /etc/pam.d/common-password" + subprocess.run(command, shell=True, check=True) + print(f"Minimum password length changed to {length}") + +except subprocess.CalledProcessError: +print("Failed to change minimum password length") + From 36b1d93304988d6dae776d6e68e477e8f64af62b Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 30 Nov 2023 19:59:36 -0600 Subject: [PATCH 29/93] Update script.py --- Scripts/Linux/script.py | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index e24a1ea..fa65c5a 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -45,13 +45,13 @@ check_result = check_process.stdout.strip() try: -if check_result == 'exists': - command = f"sudo sed -i 's/\\bminlen=[0-9]\\+\\b/minlen={length}/' /etc/pam.d/common-password" -else: - command = f"sudo sed -i '/pam_unix.so/ s/$/ minlen={length}/' /etc/pam.d/common-password" - subprocess.run(command, shell=True, check=True) - print(f"Minimum password length changed to {length}") + if check_result == 'exists': + command = f"sudo sed -i 's/\\bminlen=[0-9]\\+\\b/minlen={length}/' /etc/pam.d/common-password" + else: + command = f"sudo sed -i '/pam_unix.so/ s/$/ minlen={length}/' /etc/pam.d/common-password" + subprocess.run(command, shell=True, check=True) + print(f"Minimum password length changed to {length}") except subprocess.CalledProcessError: -print("Failed to change minimum password length") + print("Failed to change minimum password length") From 6c59b0f79f04bfe63c7abe841f351d4386aa6e54 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 30 Nov 2023 20:06:35 -0600 Subject: [PATCH 30/93] Update script.py --- Scripts/Linux/script.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index fa65c5a..1884387 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -1,6 +1,6 @@ #script -import subprocess +from subprocess import run #disable guest run(["sudo", "usermod", "--expiredate", "1", "guest"]) From 509c67d6e59c2eec9fcf73408f5acbca6aa71a6b Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 30 Nov 2023 20:10:15 -0600 Subject: [PATCH 31/93] Update script.py --- Scripts/Linux/script.py | 19 ++----------------- 1 file changed, 2 insertions(+), 17 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 1884387..047ec58 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -13,8 +13,8 @@ #Install Security tools run(["sudo", "apt-get", "ufw"]) run(["sudo", "enable", "ufw"]) -run(["sudo", "apt-get", "Clamav"]) -run(["sudo", "apt-get", "Openssh-server"]) +run(["sudo", "apt-get", "clamav"]) +run(["sudo", "apt-get", "openssh-server"]) run(["sudo", "apt-get", "libpam-cracklib"]) run(["sudo", "apt-get", "bum"]) #disable ctrl+alt+delete @@ -40,18 +40,3 @@ run(["sudo", "systemctl", "start", "ssh"]) #change minimum password age #change min password length -check_command = "grep -q 'minlen=' /etc/pam.d/common-password && echo 'exists' || echo 'not exists'" -check_process = subprocess.run(check_command, shell=True, capture_output=True, text=True) -check_result = check_process.stdout.strip() - -try: - if check_result == 'exists': - command = f"sudo sed -i 's/\\bminlen=[0-9]\\+\\b/minlen={length}/' /etc/pam.d/common-password" - else: - command = f"sudo sed -i '/pam_unix.so/ s/$/ minlen={length}/' /etc/pam.d/common-password" - subprocess.run(command, shell=True, check=True) - print(f"Minimum password length changed to {length}") - -except subprocess.CalledProcessError: - print("Failed to change minimum password length") - From 3562270a5b8da29e955cb60ea9d134b0030d9574 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 30 Nov 2023 20:21:58 -0600 Subject: [PATCH 32/93] Update script.py --- Scripts/Linux/script.py | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 047ec58..2afdd8f 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -13,10 +13,12 @@ #Install Security tools run(["sudo", "apt-get", "ufw"]) run(["sudo", "enable", "ufw"]) -run(["sudo", "apt-get", "clamav"]) -run(["sudo", "apt-get", "openssh-server"]) -run(["sudo", "apt-get", "libpam-cracklib"]) -run(["sudo", "apt-get", "bum"]) +run(["sudo", "apt", "update", "&&", "sudo", "apt", "Upgrade", "-y"]) +run(["sudo", "apt-get", "install", "openssh-server"]) +run(["sudo", "apt-get", "update", "-y"]) +run(["sudo", "apt-get", "install", "-y", "libpam-cracklib"]) +run(["sudo", "apt-get", "update", "-y"]) +run(["sudo", "apt-get", "install", "y-", "bum"]) #disable ctrl+alt+delete run(["sudo", "sed", "-i", "/^exec uim-systray/a Exec=/bin/false", "/etc/lightdm/lightdm.conf",]) From 59ccc13d631c08da2f663a3d116bd9cbb37eb498 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 30 Nov 2023 20:28:29 -0600 Subject: [PATCH 33/93] Update linux commands.txt --- linux commands.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/linux commands.txt b/linux commands.txt index 174bc66..0642505 100644 --- a/linux commands.txt +++ b/linux commands.txt @@ -1,5 +1,6 @@ sudo usermod -a -G examplegroup exampleusername +git clone "https://github.com/traceback6/waffleplus.git" sudo apt-get install -sudo ufw enable \ No newline at end of file +sudo ufw enable From 0e29b81a06169e99db89c502c68792620ae03679 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Mon, 4 Dec 2023 11:29:29 -0600 Subject: [PATCH 34/93] Update script.py --- Scripts/Linux/script.py | 2 -- 1 file changed, 2 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 2afdd8f..f5aa419 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -16,8 +16,6 @@ run(["sudo", "apt", "update", "&&", "sudo", "apt", "Upgrade", "-y"]) run(["sudo", "apt-get", "install", "openssh-server"]) run(["sudo", "apt-get", "update", "-y"]) -run(["sudo", "apt-get", "install", "-y", "libpam-cracklib"]) -run(["sudo", "apt-get", "update", "-y"]) run(["sudo", "apt-get", "install", "y-", "bum"]) #disable ctrl+alt+delete run(["sudo", "sed", "-i", "/^exec uim-systray/a Exec=/bin/false", "/etc/lightdm/lightdm.conf",]) From f47d2c24c9f7aae0ac93b9e4bf5399846e665aa7 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Mon, 4 Dec 2023 11:59:05 -0600 Subject: [PATCH 35/93] Update script.py --- Scripts/Linux/script.py | 2 -- 1 file changed, 2 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index f5aa419..15cb46e 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -21,8 +21,6 @@ run(["sudo", "sed", "-i", "/^exec uim-systray/a Exec=/bin/false", "/etc/lightdm/lightdm.conf",]) # Password complexity requirement. -run(["sudo", "sed", "-i", f"s/^PASS_COMPLEXITY.*/PASS_COMPLEXITY {complexity}/", "/etc/login.defs"]) - #remove wireshark if its installed (User is responsible for figuring out if wireshark exists.) WireRemove = input("Does wireshark exist and need to be deleted?: ") if (WireRemove == "yes" or WireRemove == "Yes"): From 146fc14a1b1336389021a4121c964f737e547140 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Mon, 4 Dec 2023 12:02:26 -0600 Subject: [PATCH 36/93] Update script.py --- Scripts/Linux/script.py | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 15cb46e..301c7b4 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -23,17 +23,17 @@ # Password complexity requirement. #remove wireshark if its installed (User is responsible for figuring out if wireshark exists.) WireRemove = input("Does wireshark exist and need to be deleted?: ") -if (WireRemove == "yes" or WireRemove == "Yes"): +if (WireRemove == "y" or WireRemove == "Y"): run(["sudo", "apt-get", "remove", "--purge", "wireshark"]) run(["sudo", "apt-get", "autoremove"]) #update firefox FoxUpdate = input("Does FireFox need updated?: ") -if (FoxUpdate == "yes" or FoxUpdate == "Yes"): +if (FoxUpdate == "y" or FoxUpdate == "Y"): run(["sudo", "apt", "install", "firefox"]) #enable SSH sshEnable = input("Does ssh need enabled?: ") -if (sshEnable == "yes" or sshEnable == "Yes"): +if (sshEnable == "y" or sshEnable == "Y"): run(["sudo", "systemctl", "enable", "ssh"]) run(["sudo", "systemctl", "start", "ssh"]) #change minimum password age From 4f35f8fa8b6c4b4adceb36be792c4283568536d8 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Mon, 4 Dec 2023 14:53:21 -0600 Subject: [PATCH 37/93] Update script.py --- Scripts/Linux/script.py | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 301c7b4..52c9e3b 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -1,6 +1,6 @@ #script -from subprocess import run +from subprocess import run, Popen, PIPE, check_call #disable guest run(["sudo", "usermod", "--expiredate", "1", "guest"]) @@ -38,3 +38,12 @@ run(["sudo", "systemctl", "start", "ssh"]) #change minimum password age #change min password length + +#update insecure passwords +usrPswdUpdt = input("Are there any users who need their password updated y/n") +if (usrPswdUpdt == "y" or usrPswdUpdt == "Y"): + UsrCount = int(input(" how many users need their password changed? : ")) + UsrNme = "" + newPswd = "" + for count in UsrCount: + From 2b84da2e5a4d4ff4f08e083ecc94b7de9cd98543 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Mon, 4 Dec 2023 15:05:38 -0600 Subject: [PATCH 38/93] Update script.py --- Scripts/Linux/script.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 52c9e3b..3fd57d0 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -22,8 +22,8 @@ # Password complexity requirement. #remove wireshark if its installed (User is responsible for figuring out if wireshark exists.) -WireRemove = input("Does wireshark exist and need to be deleted?: ") -if (WireRemove == "y" or WireRemove == "Y"): +WireSharkRemove = input("Does wireshark exist and need to be deleted?: ") +if (WireSharkRemove == "y" or WireSharkRemove == "Y"): run(["sudo", "apt-get", "remove", "--purge", "wireshark"]) run(["sudo", "apt-get", "autoremove"]) From 3f8964991e6971dd6851a7bb4450835bea319331 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 10:18:15 -0600 Subject: [PATCH 39/93] Update script.py --- Scripts/Linux/script.py | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 3fd57d0..8b1db9f 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -22,17 +22,17 @@ # Password complexity requirement. #remove wireshark if its installed (User is responsible for figuring out if wireshark exists.) -WireSharkRemove = input("Does wireshark exist and need to be deleted?: ") +WireSharkRemove = input("Does wireshark exist and need to be deleted? y/n: ") if (WireSharkRemove == "y" or WireSharkRemove == "Y"): run(["sudo", "apt-get", "remove", "--purge", "wireshark"]) run(["sudo", "apt-get", "autoremove"]) #update firefox -FoxUpdate = input("Does FireFox need updated?: ") +FoxUpdate = input("Does FireFox need updated? y/n: ") if (FoxUpdate == "y" or FoxUpdate == "Y"): run(["sudo", "apt", "install", "firefox"]) #enable SSH -sshEnable = input("Does ssh need enabled?: ") +sshEnable = input("Does ssh need enabled? y/n: ") if (sshEnable == "y" or sshEnable == "Y"): run(["sudo", "systemctl", "enable", "ssh"]) run(["sudo", "systemctl", "start", "ssh"]) @@ -43,7 +43,6 @@ usrPswdUpdt = input("Are there any users who need their password updated y/n") if (usrPswdUpdt == "y" or usrPswdUpdt == "Y"): UsrCount = int(input(" how many users need their password changed? : ")) - UsrNme = "" - newPswd = "" - for count in UsrCount: - + for count in range(1,UsrCount + 1): + UsrNme = input("Who needs their password changed? Name is caps specific. :") + run(["sudo", "passwd", UsrNme]) From 92b3d55d71fdcd06e52f40fd0633d3e537c60093 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 12:08:31 -0600 Subject: [PATCH 40/93] Update script.py --- Scripts/Linux/script.py | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 8b1db9f..e0a6649 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -40,9 +40,20 @@ #change min password length #update insecure passwords -usrPswdUpdt = input("Are there any users who need their password updated y/n") +usrPswdUpdt = input("Are there any users who need their password updated y/n: ") if (usrPswdUpdt == "y" or usrPswdUpdt == "Y"): UsrCount = int(input(" how many users need their password changed? : ")) - for count in range(1,UsrCount + 1): + for count in range(1 , UsrCount + 1): UsrNme = input("Who needs their password changed? Name is caps specific. :") run(["sudo", "passwd", UsrNme]) +#groups +groups = input("do we need to make any groups? y/n:") +if (groups = "y" or groups = "Y"): + newGroupName = input("What is the new groups name?: ") + newGroupQuan = input("How many people are in the group?: ") + run(["sudo", "groupadd", newGroupName]) + for num in range(1 , newGroupQuan + 1): + newGroupMember = input("Who is being added to the group? Please enter one user at a time: ") + run(["sudo", "usermod", "-a", "-g", newGroupName, newGroupMember]) + +groups = input("do you need to add anyone to a group that already exists? y/n: ") From 67333cf58bf203e673a50bb4da62eccf1d07e092 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 12:14:52 -0600 Subject: [PATCH 41/93] Update script.py --- Scripts/Linux/script.py | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index e0a6649..a41693e 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -52,8 +52,14 @@ newGroupName = input("What is the new groups name?: ") newGroupQuan = input("How many people are in the group?: ") run(["sudo", "groupadd", newGroupName]) - for num in range(1 , newGroupQuan + 1): + for num in range(1 , int(newGroupQuan) + 1): newGroupMember = input("Who is being added to the group? Please enter one user at a time: ") run(["sudo", "usermod", "-a", "-g", newGroupName, newGroupMember]) groups = input("do you need to add anyone to a group that already exists? y/n: ") +if (groups == "y" or groups == "Y"): + groupname = input("What is the groups name?: ") + groupnum = input("How many people are being added?: ) + for count in range(1 , int(groupnum) + 1): + groupmem = input("Who is being added to the group? One user at a time.: ") + run(["sudo", "usermod", "-a", "-g", groupname, groupmem]) From 6487b24c2da0491508943fbb07d33efe83743523 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 12:15:48 -0600 Subject: [PATCH 42/93] Update script.py --- Scripts/Linux/script.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index a41693e..87b39ae 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -59,7 +59,7 @@ groups = input("do you need to add anyone to a group that already exists? y/n: ") if (groups == "y" or groups == "Y"): groupname = input("What is the groups name?: ") - groupnum = input("How many people are being added?: ) + groupnum = input("How many people are being added?: ") for count in range(1 , int(groupnum) + 1): groupmem = input("Who is being added to the group? One user at a time.: ") run(["sudo", "usermod", "-a", "-g", groupname, groupmem]) From 78b795bff8c0f8ee9622bcd3712b80f4b4c63f3b Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 13:23:13 -0600 Subject: [PATCH 43/93] Update script.py --- Scripts/Linux/script.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 87b39ae..d7ce254 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -63,3 +63,10 @@ for count in range(1 , int(groupnum) + 1): groupmem = input("Who is being added to the group? One user at a time.: ") run(["sudo", "usermod", "-a", "-g", groupname, groupmem]) +#delete users +deluser = input("Are there any users who need to be removed from the computer? y/n: ") +if (deluser == y or deluser =="Y"): + delusercount = int(input("How many users need deleted?: ") + for number in range(1 , delusercount + 1): + delusername = input("What is the name of the account being deleted? Use one name at a time.: ") + run(["sudo", "userdel", delusername]) From aeeb4d751d5727c4212a80590c97a21ba9f9f210 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 14:01:56 -0600 Subject: [PATCH 44/93] Create b64decode.py --- Scripts/Linux/b64decode.py | 1 + 1 file changed, 1 insertion(+) create mode 100644 Scripts/Linux/b64decode.py diff --git a/Scripts/Linux/b64decode.py b/Scripts/Linux/b64decode.py new file mode 100644 index 0000000..8b13789 --- /dev/null +++ b/Scripts/Linux/b64decode.py @@ -0,0 +1 @@ + From 612f931d56c632a39b522f62bb0f1d4975543fa4 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 14:02:25 -0600 Subject: [PATCH 45/93] Update b64decode.py --- Scripts/Linux/b64decode.py | 1 + 1 file changed, 1 insertion(+) diff --git a/Scripts/Linux/b64decode.py b/Scripts/Linux/b64decode.py index 8b13789..2a1bad3 100644 --- a/Scripts/Linux/b64decode.py +++ b/Scripts/Linux/b64decode.py @@ -1 +1,2 @@ +import base64 From 66fafa42841506a0aa643134e78ca585acb27fae Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 19:41:21 -0600 Subject: [PATCH 46/93] Update script.py --- Scripts/Linux/script.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index d7ce254..1b23b2e 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -70,3 +70,10 @@ for number in range(1 , delusercount + 1): delusername = input("What is the name of the account being deleted? Use one name at a time.: ") run(["sudo", "userdel", delusername]) +#add new users +useradd = input("do you need to add any users? y/n: ") +if (useradd == "y" or useradd == "Y"): + newUserCount = int(input("How many users do you need to add?: ") + for all in range(1 , newUserCount + 1): + newUserName = input("What is the name of the new user?: ") + run(["sudo", "useradd", newUserName]) From 72176a84f6dee0c5d2de83eef970706aed587b3c Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 19:58:39 -0600 Subject: [PATCH 47/93] Update script.py --- Scripts/Linux/script.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 1b23b2e..509d2f1 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -65,7 +65,7 @@ run(["sudo", "usermod", "-a", "-g", groupname, groupmem]) #delete users deluser = input("Are there any users who need to be removed from the computer? y/n: ") -if (deluser == y or deluser =="Y"): +if (deluser == "y" or deluser =="Y"): delusercount = int(input("How many users need deleted?: ") for number in range(1 , delusercount + 1): delusername = input("What is the name of the account being deleted? Use one name at a time.: ") @@ -73,7 +73,7 @@ #add new users useradd = input("do you need to add any users? y/n: ") if (useradd == "y" or useradd == "Y"): - newUserCount = int(input("How many users do you need to add?: ") + newUserCount = int(input("How many users do you need to add?: ")) for all in range(1 , newUserCount + 1): newUserName = input("What is the name of the new user?: ") run(["sudo", "useradd", newUserName]) From 41e487f86586193c22341aa6498777ad8817224c Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Tue, 5 Dec 2023 20:27:42 -0600 Subject: [PATCH 48/93] Update script.py --- Scripts/Linux/script.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 509d2f1..0da16bb 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -48,7 +48,7 @@ run(["sudo", "passwd", UsrNme]) #groups groups = input("do we need to make any groups? y/n:") -if (groups = "y" or groups = "Y"): +if (groups == "y" or groups == "Y"): newGroupName = input("What is the new groups name?: ") newGroupQuan = input("How many people are in the group?: ") run(["sudo", "groupadd", newGroupName]) From 799f979d27a78c5f272d24b24c9a6b17a7945eeb Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Wed, 6 Dec 2023 09:36:33 -0600 Subject: [PATCH 49/93] Update script.py --- Scripts/Linux/script.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 0da16bb..9b6da92 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -66,7 +66,7 @@ #delete users deluser = input("Are there any users who need to be removed from the computer? y/n: ") if (deluser == "y" or deluser =="Y"): - delusercount = int(input("How many users need deleted?: ") + delusercount = int(input("How many users need deleted?: ")) for number in range(1 , delusercount + 1): delusername = input("What is the name of the account being deleted? Use one name at a time.: ") run(["sudo", "userdel", delusername]) From 204bca594b79c9cfed277c675db5a4209ba9b2c8 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Wed, 6 Dec 2023 13:48:18 -0600 Subject: [PATCH 50/93] Update script.py From c6de34616a606dcc91dd3476b33b21c6d0eb623e Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Thu, 14 Dec 2023 12:22:05 -0600 Subject: [PATCH 51/93] Update script.py --- Scripts/Linux/script.py | 209 ++++++++++++++++++++++++++-------------- 1 file changed, 135 insertions(+), 74 deletions(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index 9b6da92..a138b89 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -1,79 +1,140 @@ -#script +# script + +from subprocess import run +# errorCheck +fail = [] + +# disable guest +try : + run(["sudo", "usermod", "--expiredate", "1", "guest"]) +except: + fail.append("couldn't dissable guest") -from subprocess import run, Popen, PIPE, check_call -#disable guest -run(["sudo", "usermod", "--expiredate", "1", "guest"]) # update system and apps -run(["sudo", "apt", "update"]) -run(["sudo", "apt", "upgrade"]) -run(["sudo", "apt", "full-upgrade"]) -run(["sudo", "apt", "autoremove"]) - -#Install Security tools -run(["sudo", "apt-get", "ufw"]) -run(["sudo", "enable", "ufw"]) -run(["sudo", "apt", "update", "&&", "sudo", "apt", "Upgrade", "-y"]) -run(["sudo", "apt-get", "install", "openssh-server"]) -run(["sudo", "apt-get", "update", "-y"]) -run(["sudo", "apt-get", "install", "y-", "bum"]) -#disable ctrl+alt+delete -run(["sudo", "sed", "-i", "/^exec uim-systray/a Exec=/bin/false", "/etc/lightdm/lightdm.conf",]) +try: + run(["sudo", "apt", "update"]) + run(["sudo", "apt", "upgrade"]) + run(["sudo", "apt", "full-upgrade"]) + run(["sudo", "apt", "autoremove"]) +except: + fail.append("couldn't update system/apps") + + +# Install Security tools +try: + run(["sudo", "apt-get", "ufw"]) + run(["sudo", "enable", "ufw"]) +except: + fail.append("couldn't enable ufw") + +try: + run(["sudo", "apt", "update", "&&", "sudo", "apt", "Upgrade", "-y"]) + run(["sudo", "apt-get", "install", "openssh-server"]) + run(["sudo", "apt-get", "update", "-y"]) + run(["sudo", "apt-get", "install", "y-", "bum"]) +except: + fail.append("couldn't install security tools") + + +# disable ctrl+alt+delete +try: + run(["sudo", "sed", "-i", "/^exec uim-systray/a Exec=/bin/false", "/etc/lightdm/lightdm.conf", ]) +except: + fail.append("couldn't dissable ctrl+alt+delete") # Password complexity requirement. -#remove wireshark if its installed (User is responsible for figuring out if wireshark exists.) -WireSharkRemove = input("Does wireshark exist and need to be deleted? y/n: ") -if (WireSharkRemove == "y" or WireSharkRemove == "Y"): - run(["sudo", "apt-get", "remove", "--purge", "wireshark"]) - run(["sudo", "apt-get", "autoremove"]) - -#update firefox -FoxUpdate = input("Does FireFox need updated? y/n: ") -if (FoxUpdate == "y" or FoxUpdate == "Y"): - run(["sudo", "apt", "install", "firefox"]) -#enable SSH -sshEnable = input("Does ssh need enabled? y/n: ") -if (sshEnable == "y" or sshEnable == "Y"): - run(["sudo", "systemctl", "enable", "ssh"]) - run(["sudo", "systemctl", "start", "ssh"]) -#change minimum password age -#change min password length - -#update insecure passwords -usrPswdUpdt = input("Are there any users who need their password updated y/n: ") -if (usrPswdUpdt == "y" or usrPswdUpdt == "Y"): - UsrCount = int(input(" how many users need their password changed? : ")) - for count in range(1 , UsrCount + 1): - UsrNme = input("Who needs their password changed? Name is caps specific. :") - run(["sudo", "passwd", UsrNme]) -#groups -groups = input("do we need to make any groups? y/n:") -if (groups == "y" or groups == "Y"): - newGroupName = input("What is the new groups name?: ") - newGroupQuan = input("How many people are in the group?: ") - run(["sudo", "groupadd", newGroupName]) - for num in range(1 , int(newGroupQuan) + 1): - newGroupMember = input("Who is being added to the group? Please enter one user at a time: ") - run(["sudo", "usermod", "-a", "-g", newGroupName, newGroupMember]) - -groups = input("do you need to add anyone to a group that already exists? y/n: ") -if (groups == "y" or groups == "Y"): - groupname = input("What is the groups name?: ") - groupnum = input("How many people are being added?: ") - for count in range(1 , int(groupnum) + 1): - groupmem = input("Who is being added to the group? One user at a time.: ") - run(["sudo", "usermod", "-a", "-g", groupname, groupmem]) -#delete users -deluser = input("Are there any users who need to be removed from the computer? y/n: ") -if (deluser == "y" or deluser =="Y"): - delusercount = int(input("How many users need deleted?: ")) - for number in range(1 , delusercount + 1): - delusername = input("What is the name of the account being deleted? Use one name at a time.: ") - run(["sudo", "userdel", delusername]) -#add new users -useradd = input("do you need to add any users? y/n: ") -if (useradd == "y" or useradd == "Y"): - newUserCount = int(input("How many users do you need to add?: ")) - for all in range(1 , newUserCount + 1): - newUserName = input("What is the name of the new user?: ") - run(["sudo", "useradd", newUserName]) +# remove wireshark if its installed (User is responsible for figuring out if wireshark exists.) +try: + WireSharkRemove = input("Does wireshark exist and need to be deleted? y/n: ") + if (WireSharkRemove == "y" or WireSharkRemove == "Y"): + run(["sudo", "apt-get", "remove", "--purge", "wireshark"]) + run(["sudo", "apt-get", "autoremove"]) +except: + fail.append("couldn't delete wireshark") + +# update firefox +try: + FoxUpdate = input("Does FireFox need updated? y/n: ") + if (FoxUpdate == "y" or FoxUpdate == "Y"): + run(["sudo", "apt", "install", "firefox"]) +except: + fail.append("failed to update firefox") + +# enable SSH +try: + sshEnable = input("Does ssh need enabled? y/n: ") + if (sshEnable == "y" or sshEnable == "Y"): + run(["sudo", "systemctl", "enable", "ssh"]) + run(["sudo", "systemctl", "start", "ssh"]) +except: + fail.append("couldn't enable ssh") + + +# change minimum password age +# change min password length + +# update insecure passwords +try: + usrPswdUpdt = input("Are there any users who need their password updated y/n: ") + if (usrPswdUpdt == "y" or usrPswdUpdt == "Y"): + UsrCount = int(input(" how many users need their password changed? : ")) + for count in range(1 , UsrCount + 1): + try: + UsrNme = input("Who needs their password changed? Name is caps specific. :") + run(["sudo", "passwd", UsrNme]) + except: + fail.append("unable to change "+UsrNme+"'s password") +except: + fail.append("Failed to update passwords") + + +# groups +try: + groups = input("do we need to make any groups? y/n:") + if (groups == "y" or groups == "Y"): + newGroupName = input("What is the new groups name?: ") + newGroupQuan = input("How many people are in the group?: ") + run(["sudo", "groupadd", newGroupName]) + for num in range(1 , int(newGroupQuan) + 1): + newGroupMember = input("Who is being added to the group? Please enter one user at a time: ") + run(["sudo", "usermod", "-a", "-g", newGroupName, newGroupMember]) +except: + fail.append("Failed to add groups or users") + +try: + groups = input("do you need to add anyone to a group that already exists? y/n: ") + if (groups == "y" or groups == "Y"): + groupname = input("What is the groups name?: ") + groupnum = input("How many people are being added?: ") + for count in range(1 , int(groupnum) + 1): + groupmem = input("Who is being added to the group? One user at a time.: ") + run(["sudo", "usermod", "-a", "-g", groupname, groupmem]) +except: + fail.append("Failed to add members") + + +# delete users +try: + deluser = input("Are there any users who need to be removed from the computer? y/n: ") + if (deluser == "y" or deluser == "Y"): + delusercount = int(input("How many users need deleted?: ")) + for number in range(1 , delusercount + 1): + delusername = input("What is the name of the account being deleted? Use one name at a time.: ") + run(["sudo", "userdel", delusername]) +except: + fail.append("Failed to delete users") + + +# add new users +try: + useradd = input("do you need to add any users? y/n: ") + if (useradd == "y" or useradd == "Y"): + newUserCount = int(input("How many users do you need to add?: ")) + for all in range(1 , newUserCount + 1): + newUserName = input("What is the name of the new user?: ") + run(["sudo", "useradd", newUserName]) +except: + fail.append("Failed to add new Users") + +print(fail) From 6cce6b83787b87bf644f972070c53a4bcbee85a2 Mon Sep 17 00:00:00 2001 From: Justin Wright Date: Fri, 9 Feb 2024 19:23:28 -0600 Subject: [PATCH 52/93] Update README.md with more current info --- README.md | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/README.md b/README.md index 1f646ff..c1100de 100644 --- a/README.md +++ b/README.md @@ -4,12 +4,12 @@ | File | Added by | Desc. | | :-----| :---------| :------| -| Bash.script.for.CP.txt| NotMaxwell | Runs on windows, no known bugs. | -| Linux CyberPatriot Checklist.pdf | zumlar/SavageCabbage39 | Should have all of the to-do items for Linux. | -| Windows CyberPatriot Checklist.txt | aidantheunnammed | Should have all of the to-do items for Windows. | -| Waffl3.ps1 | Justintimefordinner | Bash script, unknown usage. | -| LinuxScript.py | jman5213 | Python sctipt, mostly incomplete. Can be edited [here.](https://replit.com/join/fbzrymvbux-jman5213) | -| TRACEBACK_PSSWDS.csv | aidantheunnammed | All our passwords, 12 characters with all specifications. | +| Bash.script.for.CP.txt| NotMaxwell | Windows/Server 2019 | +| Linux CyberPatriot Checklist.pdf | zumlar/SavageCabbage39 | To-do items for Linux. | +| Windows CyberPatriot Checklist.txt | aidantheunnammed | To-do items for Windows. | +| Waffl3.ps1 | Justintimefordinner | Bash script | +| LinuxScript.py | jman5213 | Python script | +| TRACEBACK_PSSWDS.csv | aidantheunnammed | Replacement passwords | \**All checklists should be in the shared Google Drive on your school account.* @@ -18,11 +18,11 @@ | Username | Name | Jobs | | :---------| :-----| :-------| -| Justintimefordinner | Justin | Team Lead / Linux / PacketTracer | -| jman5213 | Jordan | PacketTracer / Googler / Windows Server / Linux Scripter | +| Justintimefordinner | Justin | Team Lead / Linux / Cisco Packet Tracer | +| jman5213 | Jordan | Cisco Packet Tracer / Googler / Windows Server / Linux Scripter | | NotMaxwell | Maxwell | Windows / Bash Scripter | -| aidantheunnammed | Aidan | CyberPatriot Notebook / Windows | +| aidantheunnammed | Aidan | Documentarian / Windows | | SavageCabbage39 | Ty | Checklister / Windows Server | -| zumlar | Gideon | Linux / Linux Scripter / Googler / PacketTracer | +| zumlar | Gideon | Linux / Linux Scripter / Googler / Cisco Packet Tracer | \**Feel free to update any infomation here if I got it wrong.* From 8b0f8b68343d233f4a446a008c3242ee9d4003fb Mon Sep 17 00:00:00 2001 From: NotMaxwell <142256213+NotMaxwell@users.noreply.github.com> Date: Fri, 20 Sep 2024 08:41:27 -0500 Subject: [PATCH 53/93] Update SCRIP_WIN_CP.ps1 change from quick scan to full scan --- Scripts/Windows/SCRIP_WIN_CP.ps1 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Scripts/Windows/SCRIP_WIN_CP.ps1 b/Scripts/Windows/SCRIP_WIN_CP.ps1 index 32845d7..1d7d7e8 100644 --- a/Scripts/Windows/SCRIP_WIN_CP.ps1 +++ b/Scripts/Windows/SCRIP_WIN_CP.ps1 @@ -47,4 +47,4 @@ gpupdate /force Disable-localuser Guest Disable-localuser Administrator -start-mpscan -scantype quickscan \ No newline at end of file +start-mpscan -scantype fullscan From 39977d1af65646e65fdf2c7896ce47f00f099748 Mon Sep 17 00:00:00 2001 From: zumlar <143119610+zumlar@users.noreply.github.com> Date: Fri, 20 Sep 2024 08:56:49 -0500 Subject: [PATCH 54/93] updated ssh to disable if necessary. --- Scripts/Linux/script.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/Scripts/Linux/script.py b/Scripts/Linux/script.py index a138b89..d840767 100644 --- a/Scripts/Linux/script.py +++ b/Scripts/Linux/script.py @@ -61,12 +61,16 @@ except: fail.append("failed to update firefox") -# enable SSH +# SSH try: sshEnable = input("Does ssh need enabled? y/n: ") if (sshEnable == "y" or sshEnable == "Y"): run(["sudo", "systemctl", "enable", "ssh"]) run(["sudo", "systemctl", "start", "ssh"]) + sshEnable = input("Does ssh need disabled? y/n: "): + if (sshEnable == "y" or sshEnable == "Y"): + run(["sudo", "systemctl", "stop", "ssh"]) + run(["sudo", "systemctl", "disable", "ssh"]) except: fail.append("couldn't enable ssh") From 9f25f30da741c29cd59bac74e42679ad2c79b187 Mon Sep 17 00:00:00 2001 From: NotMaxwell <142256213+NotMaxwell@users.noreply.github.com> Date: Wed, 16 Oct 2024 15:18:26 -0500 Subject: [PATCH 55/93] Add files via upload --- WF404 Ubuntu Checklist (2).pdf | Bin 0 -> 61446 bytes 1 file changed, 0 insertions(+), 0 deletions(-) create mode 100644 WF404 Ubuntu Checklist (2).pdf diff --git a/WF404 Ubuntu Checklist (2).pdf b/WF404 Ubuntu Checklist (2).pdf new file mode 100644 index 0000000000000000000000000000000000000000..2039cbeea8a5fff9076b39d1048ad19a2b265814 GIT binary patch literal 61446 zcmd3NbC70DvuE3wHm2Rvwr$(C?Wb+qJ#8D)wykN~wry>{-~DdfyK!ST_RoFdJaNvc zs?4ga%#0J6^-B_YVNn_eT4orMxwDfU7zP4*0y{%X7;bJlWeb3{2?4p9C^J1Xfr_EC zEx?&T$lS!p%G$ySKmkK1?`UW2Y-Hj{K(1tEVL0Rs%3pbP<>tevBcf%Sh4V*Rf{q88SG?@8!HtqlMs z!X`#`#wIXy(k8ZM0CNInHb#10UIHh8qltkHj9cb~&WY`>W~9&Rl4;mfQd&>G8bJjM-g`Xn5R_P~- zxn=n}WoNZ`WB)SnkQG`|8&LQ&JO?*Phj!-)kq^T0bh;<%fIsBP*7x-bhx9~%E6WUmoMdc)xeGMdC0FojH2QTJZZ2*(sgNgN_g#R`G=2pSJe6+Jsyg0UEW)&+0uhTYDmMU(D# z6JARg7^MSP+07A-$t07sAB=&2{AjRF@9(SaX)uK7GjjJJV{G?9`F=P+(15`tJJA+M zDwPyo=bz~~EHDUqhEHq_0y4GU`(krmQw$5ZKa7A%PH}r~ny3R6)F+1o&4E`fD$!Y=kqC z@PK&bT+)3I!mUNmyZ+y={3kt*SfI+G)XQLK^srK^wFGRf{nEsimX!1y%Ox#Gepvke z*t~uIDAN4fdpCk&8ul?gJ(*(WocPAS`QD)t@xG3@cjlTy@qH2GSu6XtqlA5S#iRg4Q~UuLtN7cc_*oY$V`-W zyx`2M>md>^0FTyG+>tqG`~rFv z`Bl7>5=?dC(PEtmbV-|%rl(Cx4Md;G4-`z@3_W5$IlDh(fKo%Q+k0@UoW~7X2+W3p zdS);9hxl{f<*LTC?<{hdA5FRiL`5Cqw)d^BZHv3%CzKCVh-1*rfecN`Pn}+wL;mWS zLUu%BI$hnXre;>)=aw$X1$A!P$P$>9{*EtEeT_mWUDqLn+cE3_&r;<{b7vf&y&*D@ zXLv$@Tq>n8HuMRkcGwRHocU19sYoYv2t}x(!@E`31m=uYspunMULA>WUI^bVs;V*m zaz}`*zQOWHJhqV|;7|9LJ^#GH!&?s^>r|0+!B6gmB@-!RDHtz^5JYr?E_+xzVrl6) zlJR$ED0N7=90(G4OxT~W^t?TPB=LH(M#$)k(%%4j&OWv>nT<0(K;(haQy`Y=Zb8cW%IiA0)$w?an&vLcIcO9X7>1}cug`!x(6WiH@U9?3xy7a#4l z=tXUivssiSFD4ud5gfl`A{SVNxC`3uj1+mD%|SY&T*u1tG_h1c0Fp>YIEWOL!(C`4 z9iw}QgE?OZN2omWg6a<#?-)9iGmWN}r*Z)-S`+inq++I8iwRx)X=)6e&+>H{@IOs0 zHqTWkZcPgAPT`NEUU5&FZHL@)%E7}OH)UEydMSf}`>AS5@RY*xAvjSUcBxLBqzK5s zBx=M}J?eryPYq61)mK2L5yZ0AC$p3*rRRpzT{QbZFk@W{A9PD*tvbZvN|8DV2Qczk zr0HXTX}tKbMD)72a>!^{@gfAkvhLEk`KVkAaA2pk3$5OACCn1T=$7Iy16MI2Lm%1N z1unPyeM5xJTXu8OAcSJ~13{)j&*w6z6=(FbELaT|sOy-eHH@?gHsyqapRY;#wP~FW z0R-Z_S^@gidQA=M7?0@PYBoy0@h2lib(9ncxrP8Dnws6HW6}y!d4FRpDmqHeb<~A6 z78=r-sbxlMg;6$KUd8(e_v!GF;1Fosev@n95unYf9ACh1hs+u(EJUnq3F|(UlU}Z| zG^|4z98Iq;Y0L4vsA6AvD&JTD>1tHjsUVd8P&VK-6_k&O@vh_kl@Wc=g#!s(q)c7p z#d~77nh;%*31&Hn$=nyA^2uSjE0~;YGNhqUV5#!3AC^n~+!*)@Z~72FYr$-Z#ed16 z6(0%TT#=4jZY1u^Tb4KTqT`K~v_wP4m9Zj|-q!)_sVw6p-wstd6kXA{*4aBROxxI# z6GKSZEN_rkC&9u`KT&=R7Nu+m&$x|0<6x;7yy6v8wUBddL8CfiBj=Z^7Pc}rk)_79 z$;OnY^y0n*gPn8Tl#JYQ9*-bLmVHg?>PT-UlVEjYD}{SRHh;G^$qJ3yf4AAYw#=wgZnO*xnJeHYiDN zE`|YKXlD*-B9x+!p`8${ifaR(keTPncBtYJXOgMyS86ciegmM6a5+6Rr+fktZv# z9Lxgb`LwD!fU_BkPn4ikcwNA@Xd5*O)Z+t8J=E>;US%42%XQ0VLnvQLKI}blUo$Bm zC)|}n?mK>8GZ&kB$ZHtZBj=%{dyZXnQ>(P#8I#J>PqjRv(y-Rq<^qn~5i?M#-hk09 z2d5TSU4=%$2J1j7A1Y75%gZnFImwh)F)KyxXkKWvZeDx6-uHDZ1ZrrGvRxprV!$Fp zNi+=U1zmV)$rFrvaVy~>yUCB#DNRg)-T-y0ApIj_A9V9NE84~zq!;asx1&i&9PZKu zbow+@j~rJ4I4ZmKk$uSpCYvy8KX=W&fu(L$dB-lDLP2&XOp~9yG6)+|0prii!9K@Da^t>538;|DfKzhlRl&czGkbKPJ@{&ofUpt+Oq4K_lxIy@J=R# z<~MtW!Rl35(0E+UKtkNX4HP6Fs;ov*@KW02@+Xy&3PsNPAe`7z73}O;15DUmm3a@Y zP3e;BDjG?4@IN}hJ72glk1x^6~uT+N^N%F-N1 z39_7XKUMx^!^}K70qa7r4BzG-aGjer7=l#In?#&#P z&FwC-v;*e9rH<9u@k8)Xe^q8My3`c?u@)j}vgEIDt3ZB!m~|C%LPDgYc9R;O&u|;Z zpo$5Pek@nnfBZ4!i5U{fT4pYOCgymlCB$ivVV7OoFm}R~6XI1d?tQ!LO3X$zb?^bB zyD3|g&a$+n((OtBoMa-k`_f^(8b`{$5#RrZ(c`9RUPla$H<=Ogw~2aye~a)~G}qQh zV`60$zspC|QWlplpn3@HZKRyqR8vi%XwUOc9#z08iEJpz5$wFP$$6xI!CA^SYrZ+9 z+8nH=Tt5GdGNN%S!+Oe883Ms+2*`&;v^>r1^0?AwRbJO#4I#X~-4wT;W?G3x=mN!u z!nMPP;&#@ZbmO_I^DQ(DD6)tn7J2*c-t&ajw)F^-hy4|d42~*jv%7Y}j~`B+O!Qin znr`%JzqZ}@Rr)!P=*B2krM|zd)yZEQkT>Q#a>}U4b5n_sC7soAT{utTIQelctIVD8_HCDU7rN>bf9|61vcWy z=C2|*JSSHUe`h?ev9#C7Jq;^Sd2A}!>e4553=Jypxqsp|`Y1|Yom_BXWd6hhTV7ix zYu=4CZrWUa)t`{|cPoLcTK!`)LIC5qus`UES`Q;xjqllQWhCN?yWzxj=F`>g+SS+4 zsWtV{z;uCA-+jN@CMT<3;0uCKPUb0dG#JgAZ*%1%gwnL^aiq}ZGb8B9#iQlSh5u9f zd8GKEU(UEGl=&||+5)_Ez#>XVs%|TMwUG2(d=arK-&Rg$+{&rlr$h3~Ktpd(>>}5A z%627KL+qs`78ZtzD+fmP&s&CfjZ-E8&;9{8BJ)86F_w~^N042fw4 ztxU^*YijHzO!scIIA((g;DBAIu&lZs&(aZXH80V{9Uv`^`9zrAUnM#eKp7$vB|8pi zHfN%E^h*m3NprV)BaOUA;ofgg5TA$^#pwza6EvnPDDx~q3r<`suXb2Ue6si*_!Ftx z$&c0ybgO^3jxkNnbqMLGTRszi{^BV_e>72%tRxXETah{? z@;IFjS9+Vx*3iP;Kf4VU-li*AB0E3pDPt*!MPJc$uUhVg?aS#yZ&!O)P~)?(pQkhi z-6H$+^A%QtF0TG-D`N*21uG`qE*d7eR5OK9pR z?gjB`_9yJjDP|r^GeL#NuiBQ~v#R-bS6G0>^)%XYXEh#cGi-*<6JJSX)5pW^<92!2 zLcNEb55)1h08+iZ_gx@9v20CJpWSBsOpW`qJ4l-g zGdpm=T;@kclL&@OkxreD;{gur(D?aZOa(IH3&jSy`?Yk)oy0+UL#Yp_Y!_yvTtK5X z9fB?fgonxB4`%M21Vp)LtlEMzD^;fKq8w^t@i?JA#_QLkVd6mSkgkGlp@YTqLCX=& zua-TC)GL|gc$iGtHIM94gt3ikp8e!hAyuuX&KMKmcLK9Y_G`3{udF!tZfJ5Nr@?ZG znaagd_%NQ_>-gll5#Ea$r|!FW4&J)FqnFJ`%_upeqMr~hznFh7L5_WP;)7TtrX6C^ ze1WGmX-yzJHHe{k@?FK9DsEmyi{H>>2p#0UUW7`y0U|1YtTdKE!Zzj)Ecqd#?54GICjFSECA?tE?Mqj3mwk<&Rx{h4&l%5#)+p4*EX z5+Y8=`#adJ80F6O)ED>1(N|hPP>JNMMd^`V27Q9DpdVSW%20=- zg`DV6A{+tlAts{tw`_1EcxG@Tx8&e2_0Nvn{c8BS6PRVT41SS6yc(p%&%+3A*S%VA z;p73~K#}3aGhC(Jf>bTaU>=_!c?IsyM*!^&-AFclOmE8s1B@;BqE>f z0>^N9{Igep^&eaW5$G2|n7DsiQ;?kF`R9>DVfm=*;v6v*#3=sW2AhvE`WPD|v-eH* z&_L%{_f`~#{Z0x?n6WSs{LU>e zKR7(tJ9rOi2`B6v(o2>Vk7{&OoZFGWUs%qbL4ZAE8w@Q4ZS6*Y9!s!>Um0N(8U&Vj zSO^^K08~R66V|4a;E3fd{5Y;aEYhp)I1(($LZ441nt0H7H8vH}pV+EJ#uOBt-zXjr zoozaW!4_o{!`8@-VFYAy;Dy{`;->JgK(Nf5KfAC))S56|WMoRkBdat4E#5Vo3zHU5 zttE*QbGUSp-sCS2efY2&+ED$QG2+NECq+9|XJTDx>RmMT5DZA#ux1Q3>*5efz{^$_)ZeP7=n*wHPFXn?-fFf9~3 z0XY3e+Cy;@@<<2(r^qn$iZua+-5LN-8J?rizr!Pu3RMI8Ne_b2LKPGHBpW{IZp;Wk#)IWgaD>C%e@n zZ-g_N3)YYqpcVv^EyGpaLR)WLny0T)tomeDz&RveKwFfz?wqYkQIs<`pr*b@IYaT^|zCay3vmDV(WFH>mqLXGQ1S?pcHai_OXiC{^pR@QsyaV@Zj|xs0yEn_^%g2+gdE%xJ|JuokWPK5VNuh z!{s0NY29RJl{^3T<}KH}TGYJc#zl>B)S{H#9;n`Z)OiPKq*wI8rgSh7r-EvSG$a3r znL?W8z@@!Zs?$^6F3<~VFd{8^EIJx9-Zns4lugvLH!?YLIo*?8x_p>&0rHeJM6RFQ zq`@tjq}lpPlU_?Om})xW!x<*K4cG)r0V>(l#lf*-Yg(y4%2tP_fJ+xtMeQtyCCrlw zT0g!kvrHv^2{w~_@#9qYT3fxtB2MKyY^kKI7A+vh=HWMISaWl8Ap*WH6S+TIoAC@) zz5(D#c+q!p3g|EnGl-Eb%^|wS!zLMl#@nUl%=~V{Cb+o1Z>SQadrN9;{BkGa^`+yu{KQ;!UifI%xMqvlw7Qxu1*WR1Pmb#NTCZfOSfs6?R2b9FNN z%DamMiZ2B#)72f^a%ookl-XAk?537g=$J_+Lg!|gHSbIoC+6ko+@RohNzC>JdSv=A zzx0eA%H%wOoPUntM*VfV$_7*?d!mw z%S_*Ri}OT&@H#o0S)KOSs`CDj&$0wh#Qf7kXiuO6nu9fh3Ur^;bcJ=^TdVOqJ~{2GjZ#{i?U+GT}Ix z*OV^v=fVSmj$DPCex@g9GiaON(3r&G!1Qjy6?ye%zR(Vi)+o7_`*Y>nE`;eHV7YlI0zeeXCH9 z38J)N*;_(cdRiRx433)p-cqvW@t4TfQWjJDD%3eK_ECjTiznIJq<~&E?)Bs-SNs>= zB;rpictY6Cp194T#UDMvKeXs?h#7aC*N!`f0aF8%9EoC)G}y9QPGg8ZGj|?aKG!uQ zt91aQMd1hB{Z+&^oeO{a1OelLB$@-qa`?@f(mkih%Br_azV~g<=ic=AW%}Vr+YDL2$~6G3kB`K06}$&J?us%u3}T&g?4uCAcj?@D1|HO#&Xrr45<^&(Ngr=+x$ScvB;bvUF!Yh zBZvAzMhHN>$SCWfYNF9zr@gWyJe!+kv8rB&;*tNymEVVRWBKO10vo$-)Qh>LOUgX3ZEbbh`kNasU$6*#j z4jBZAKMdN;5QTG~o)RneA9Z++DzF*8=7aVhv<=>Cge)-JUQ7o(a7ouX615A-$~Fp- zTk4#_2Sv@^0#ubK-9ES*lQO-+qGd`B7BDyqAd=n+*>aG-)us6vnY}m4IC=T#EB2s2 zSaIxU$hNAE-QPb)@sh@WD&}rRtYk{P>M*vrR9Fsh%T>;{fkG=rcXd50i>a=Pz}lT7 z(cmjdSBgSfcMM_Y@2RI(=e2tNG>X_n%RcAKt4qI`wLwRS2*&OW+ngx%IXgbsQ_Vc` zru%!*D53TfReuX$dQ8u;p5zb}xk&fzrG{xw0Dt{i}8`pjCUNrEx1CoSC~IXZ&8(Lc7-w z?|)_B`@q3^e}Cz}v(U5Vl6clNl1<~E-&MWI-)&VIaFjhG$p1ye%$&WrlxmhQ(aNAO zvFQL|&KX^iCs__(SF>=WSS^cv6}l|(Cl=Lo95_~6%gQH;dy3Y7*v;N9KhDUh>l8Fx zv-ezz%AfE2603j)O?-dedfPn6oT4p3(sBd3ol6*n>Q|TiJNd_F6#x6jnmm5!rHX(EPCeL z>!N_&1M=p!1SEdt*qX_R&v9Z^+0LdpNgJ`az-WBpnX=t=o(>VaU&JQoihEQ&w-a2T z=~necZq{yTt)t<`xYy;&Pg%5aANnK@1eE#7^G0LCc-FT5af$3d+RLh}0R#=RSDEriydZ1M474J=Fk&l5N+I6taSEeDYALNpTnLCUh|v zA}?P<5n= z>CK`zd?9Mjdj9#JF)YJ>gMj?suop}WEKL7<5PK4X^NqdemSdpPPaot|{{~+qP`|ha zcnAJs)hFQF?cj?uoEn$CnnaJy79ti&s7+{Rp{`ROR)gfIiF|w`tHEzA+~E8CxX&qx zb9eW6pTp~``uu#WZvW8xeE;~4VI7{{d~;4c!B+%~S3X{4xgKZz#mLA}5mA(nev1C1DgpUEcTTV*CWfEHCRA{wP4G?QdY5V3#wAFbHcG70$v>uI z!w4j_U!yG13kww4npBfo1Z*iyNOCB(jfqX^hkOUcF(dD{3+@q@53c|dbKJ{28#YG# z)AK83&J8~&$LG^foAIZL@4?2Mot%A?-+8@1%);pIWoyiB;tqcxpLl8ek?-XvGNJG5 z+2u=Y$<)+a-UyZ@G>L8q{g<%mz?0BGQVOB9Ou6Y+?dRA5cu8JuZ%dpoQ@LE=6Ei!x zaDVN!U?A@|)FCx;2*qKQZrn?WHdUX63M=C`Av^Tx42AP_*-zfjjBIqXS1gkQv*%bHx)hua_WP zm}V(pw-SMdI1Q<81z209bln?wtqc1yOwiUmk*ZmFNZi~c4czmmI9yde1WRqwdcu!b zg#pOLfV4eScYeWH1Md#qa=o#QTu^NKRpfvE*+m=^4}pqUvG6m1 zcQb2pbTgnf(-@mP>W6jmiLzM5#1@1bNRu?e%86-6lt8oc{qiW^%1Yw!8Lc%bWxsUK zC~u)CPHcGrIlZ;toO4^8-spKYF+YGq|E<|DJAFfCJ3L&lm_^vvs(6;*HUhc_l4jO9r=>~kcq%l&rV<3K& z@2&XT>|Ad&Es?{(sS4UbsJi!+;lobYraEKw(LSd>#s=U#gV?Ux(volAMt74{-+d{k z9ca>f2B45O{(Rg8vINQ~@pzV^b{0!F^-%MvT)}Lza%=+8l7qd>2+r8IR;F>?pRZxk z_{p=*8dD!v$TX&|ms^+23aQ)jlgq~c-FQ>q zt%oEDm5DiXXCr8Te&Kri5;g`F<3KS3TX#_nfsSCQZ`rTjwRyeBVesPGV!f}nkpW9U zTnyT!<#TLV9IjD&QlgR;b6# zbhVM3{XatuXyjm~CRB*6aH6tejwNTv~^N8ttnNM^FV< z>EH|7VadogKY(c~fU-i?UrpNwIyMV(=N!1Yu7l4R<@2Y3n61ut01l?#RAAo`>F!I( z*9L!Oso&w2&ZBIG+H05l=ek7ep0`Bc-Ntt9c?g`N!$Cy@x?2zbHqNmLom;QRqH58E zYJFU_x;#g)+Qq!(w%Q00LM)gH8VXgG&FRi(p{5zcmRaA{2cA_$f5J`BkLs|=3>RN^ zc@$eVNKi_S6!BL)m|>&dOMY!gAc3J;Hgayk<<}+=SXbru#>paFQHqbNe2_+{<6EyS z+AZ9_vpF#nxO0rwR7%|dCm`s2r8pAA%v-v*)R6Ej^n|3_%sufD#90m$tp2fWRpDGZ zZY6`!{J^S4F!=Oa*26ON>|Fdwy$iZyQhOpI1CPocf1I~m7kV<%n;<3J1|>V$91@cU zJEzIS@_@Pgp(8nQm#W)jn9{D1{osBcYTMQ07zc(zPJp!&MrE@Z9-T3${~*p=E|Sg` z*R%qdd=-8Ve8a{^ZP7Q^VMcHDzn&ybDT
Y9pI}SQ^;Kyudh2kSB>haLMp_gcdZRiQ*VoNCFb*QFobNV7 zk7{h!+{}h@!`gMJzmht3+dM^wCnjYh7l={abL*2ntYu6VUCSv$FM=li{?aGtZt z-dvbbLX1{Zl#=RaLV_(}HCD^!X2C8ZtGanufr&|97nRmD^|80Gnl!vhmqoOMC-aRR6qs=RSCRaldkJv5!s*eV>w zSX_l&y$>FYK&xJe>+Vdp-NRfgb_mnKQGd@`60E16o~ZGR>zB+TZ=5y%u(=#yJH{|9 z!!a-QCCi#uGu^8@OolG%Z3spOC7W0qK8&SqIsWvZp$!Cf&-ci#K##k$itt=I=4*J$ zQY)5n!if9j$H*3Y*mgW`mHz19ULEQ^kVb@R-H70c6h2kqZpN7o1fk>z>I1)r`{Y9a zUI^8)diNYzkATsr%LI!e_S0vAhd~_F;pNT2l{}<2TL|N%dEoIbn)O1vW#RZ-bm*>k z5Y1n5PO+*Rc)zwcdntULtC~ScpdGE4N!+Hls)3fO3%5{( z;6;Y>j%#gH`M$UeRUAo^t+c)VfeO|rh04zzLseqURvtTQY-St2@NhJpOXuU`wBo!= zVc(&iYXcIdIrbVH=_q8DZOe8l!;IWhrNJj*;GW_@b?qc15^f0Ke$rW|(ag9$msNSE zXT=Km^XOZwKyLLv0~5yoI$TqBw>Kf6lQ%H?hJq`aIN3Qn8ksl|d}G$XG3iE1CIAAh zf5Fk|lug_K1auNM-vb5zeHZ%oT|x(jPQ(o$rUdwgmH$I3#zgQBG+pr0as2-v z+PD4~=n1~Bf9?AJlLr442LBH^8UK%R{!69*Lx)cP*u;0`1OXEaos@;K6M@#hG*9r4 z!W9Yr*&9Wj|EhXm_;0ll=Cp>UtR@~zj@Aq=jIRGlN2ji#Nx=4PZj9fud>foOEt`## zsfPtS8>_LAIf2%{I1>ElC{_kGS_XCo)^8jB@3Z`4(*N5^g$w`&)^=w9$Y%EKNB?1+ zFm%EuPT!{duSI=tgsO#!tBIq$qlxKvL5J)t9o^?3rg!V!cX=3*(_vqeu z+U$Cp0BKG6feiH*SqMm>Dj^OCf<8>5CzXImKmk|)Q%&2zz84GEfi(pSZ3t@^Gky>Y z2@Mzn2V=-a)C31?h#_WA$Ruw4jjyDQ3+$ou%k%EVr~B&78}}68?CknbR_-L5<#aj^ zjtM0EV}!n;sm-(l5YLR_mlIiZv?!a!2yeIzs&90?TAs!FG5=D5zU8+h#kfOU%f2)5s=`Q6sbN0btlbd7bSf|3X>{2~X-zl#LHE zhtw{Yc9*=*o%|8e^+p5PRjreP8*KBcWov1h)+IZ?{I*OkiR$Nlw9#75!hYyPZqNI9 z{U_QT;B(X9@7`Lr@%G@nDgz=_4MDmQN~6NB=990yZ4&O3d>LHfu70$x{EeGCZz?z{ z%}JINfS4@<{@Zn~5k$Ba57JVimO;ZdMYx?j`b-j{_e2awl*NGa#tWtNJe(|ZSQKhfUlS2~gFL^e)Cl677uRg z^?RBprCqA-zB_w`D=3BAiS%IuTO{fq_UOs%&p5HJvb}9bd#%7@hlZ7rH>dXz0q*M+=NukV#td=ZOA6Cz+dT+VI5Z)@f+PbksU?kObShw^d2ZTSsM=pl%8Ax^=4>XdL z%yPXj!(W!-8%uWFOQ_(x$Bf9%`?|Rdcs@CX(W%#<+4?)Lm8khNL9Ty%`fpcJ?Pz-K z%6bireWB`}=}d;!AyJQBn%VWZWg7>sFp&#y`gQkjtyG*_xtQ2iswO{u!hNCg?(&7SRr_Wy2;y#fuF42)nBflr5Q|gxcdmaG z!xd+x$`-!4P4)w5ika5uqb!Jct`;JfQXW2II-rdmeDI3@LT<~tgA~KGD5XIv{bsNy z!-vl(Qqxb3vPu3>|D+fG4Z@uhIi(kIXeTfI(pIk@x1UDb> zPGYpaEaXYcS^d<2r>dk+gk;Ab0gRARuYb%`hwSQ7z93PrzutsaK#xB4E}IE>DhC04 zv&-!@pagqddu5R7hyL=`?;jbd3mhHCT{6_kC)AW}Zo@VABB`_k%=mNQsguLZh)P_= zt*Mj!%#d@fsisDpkaN`1HmRBnSwu7vSfhC5+#u% zZ~*qEJ8xEq^JKx?^rQu(=l_)oi^uh*U93!+{y2^8YlFuznp8w z%Bw4qCBRu`b7h6~!LlD*Q~62`N79@RXPE*e05hg6#Vi>B<*9X{($*x?$$W_uXBG_C zRIZZ15i{q3E9*2x^&NndgsWthVumAF_GWSv5aGNyN3rUTokf(Dc#L|PDPAIf1jf0N z92#MZbMhWx|(r`+LF#IiKWhGxY3v+g0_xJc89v;m_C3$_l6dtc68gkv_Cnp#!**@7PCt0~Ak)SLef6^PONsE?H z%UHY*(s?_Ie^}l=6yhxvc&Il&_}QND>MW_~EVd%N7RqQ=87PMGI-AZFL~X3DBV~gn zPO>{Q(I>a>B;Wepwd^Y|nkkC)HWbHjy)nz3V#Z({-q$Cjx?~S@o}P}bBneCHUstpqy}o; zZb4!EX-QW_a10#N@|_%>#m`L3}T%GRHtt5uq@_ ze&)dwQX>*_!x=ys@q!=)DTEnHz!^gAfshi!&_hE9xyPlvVQ8|yK*8qzFd)1aSccpo zJcji~LKi?1Y(PaSCd_(6uIvC@!jgyhq+THoLP_QFCByjvw@%Hp{q%cbBo|@-v2$dO zf*`Dp5aK%Yi+v{LY z*=GrCrLSEDJJjzM)CjUDK+^{eA{)dx|4!OFu)Z}zn;rJzks4&r*w@{U%1-lyWC^K6 z@5`APQv;0c=qqFuy^Tc=zXJ%u&x>Zqy^FRty#!*0UWSW?GJ|4ANmm%=hBYO!M!L3U zhc&41vzbm<3q{wV>T}Aac_P&GInw{s4#LkrVC8DYpy}a&I_h&*pG9y&$}dWJqsm0Q zfTHtrhdSzic^(h87q|qS&w$p2yF;S&i@d%R48o85NPUCV42DIb4H1D#=^=rl3m$Cc zsX?U`X@T2$GvD}*HPif3`k#L20;e2o3h~@I2C4O;sXMatJ;|?iFh0?0gQ^jBsP>%c zbM&1dePY@ASs`sgEfH%2v+2J`s>i>fc8<`Z}(wH)Ca zdY{@RgYu=_-neE8dLnoyww&b?bHiVczQ%yk3)So6Y2C2rTaUa3Zb94$yq2QYquSVk>wvHRiDV~4~`sZYk8;0cb0V$Z{! z{sziTyA5$H+=7HB)B?RTW`6N!>LP$lAN0@{GULZ59xJgIa`s4PkW25?^`+9aXOPy8 zM37v6^7q_Pep7u)&*QAXIe{g$#$4PPp1_SIW(?gZO$MLtzyBRpscoACRl_`EzXR`_LAmzWx{);FeumjY=01d6%edi6Z3;f)bilVGbp_gU zy+dyfyyxsxuCvbXY>GbPbp(=J5wAmdZp*cr?a*E0^&x`2Q+34JSNq}jWv?^UAbv*J zcl$x=)Ae-|dSUYhAR>L@J{~mn4cFk`>DUA9kU`}H`1XiF@dd};T=M0??wDOm*uuU; zzJu-vJfrR$eRtDs=d_aTNIfG4g@V0f;0U{^_f&63u3zmy;Rr6%=%arI(}!NWrXiV0 zOUh-+t8sM|d#sn07!PH8&8DJ=#bRr);GdoT%A3-*w zZz*>3(keIN*9zs%ZK=9sZ==l)2Cw%(Yj7^CF@LX}0u-(e7?m02jBh6%d0&i1-5D1j zNtl)l^`!1WlvqY6;kK7YDrGE3&1KO0N;x|?l^00upNZ(=5zxN7#mnyfEK4``bS@8U zEVASr(p&8+FRsKs^PInrrov+zc3szZn>RCD9MBfixCs!`SQ(WzcGH+R7UMYfd9@Bz zR%AL`k0~o*TTsR*oSVpp8wzjZoOi%YFQsCMwGYWqj78XNJ3W+P&74!U&C>F^{8OLK zS*YRP>zP1cN^nBxPS{vx0W$LI(34nt*tYspd0mD#`5?D=uBSne0RQl3OJtb z^7VN+LBlp&)6f?osfhFufU@~?>(@dUvfKqow{Nvjf|%@$j5#P_<5;3#FUdt=6#ARN z<@R%9<#Z!lri5#(lZ&Ui8Lh;k)N*y*H>HV;D>)~T)0Y0R>sc+}>)NMW2z%OP^4x`U zD!snErET?uZPu;)yU608sqt_oPw4tZ!)7_meICAq%^8kDcN&R?cflP9R*@Ovu9ziU zZGDL|e~&ZQrs+*}I4<3?k4mM!ymD0_?v#?Z(}GEM)f110P~}=3Ty}dRNKDKN2jQ<@ zx{AzE_L9Q9sy*%Ok$YKj06?r5tG&9l#X^=TTCsM6!5-0vmZpn*v#-hf!s5!nvQ;&| zB;Cz_Ub-L{yzB-lLJl{O%^HW+L4w%hG*uae3h0XAJ>m`QAf^nGt}wyD86cIfHoSmV zm@zkbqnE3^y<3E0K@h#kAsrH@N-56*Ljl*Yx*f&w*6)Ku7!*d448uKg~1{M?`0GzMqWIv zf5cC60a@>c)JpD;88|Ht8__w_p9GD!QN^;8&n-<#8Tc2mPwA{BK#ciGN)%|bA`!Iu z$U!V~60gT@fr;fQp0e zR~5np*IvpGrW}FaV<4`yV~ivB3wY}$M|+e6ePQ2c@@M5CzF}>qr93TM6F2t5p=IbY zFI)Y%4B&Gm$d`_G>nhy*Xra<>O0zZXEHd{^A&)e>#W6EOR{8FGckiCJXV2=)A2U5&-Bs1qC26Go zb@`Mp-d57*ecpX+>vzAhR(dN3btZ=*5loJILprG)SKJW1*GmaA0`+R|NAw0o)j5Xr zfV8!WwS-$7XQ3YMj`un@zG05-vJ5v)--q(Kp^LxO*kl-uEv^Ogx%bp)F`pHfJunua zW|&6at9A|G5EC7o?_8*>`(%)g_W2`uK)Z_JI*o2}qKMv;orM}53bd){V9DdQ9ecw6 z0G8YRiE4v;6%+fo;FPNVdp9pi)Gd7KotWnRqv?s$!oh;?>aE~lE#EgAnowJgflf1$UtSCfIs00FSyUqDWw2iL#I>BG7 zVAe|fTid*e{U-Ybu!_zrtsT}c*B0ko%RYWf3+^;ZN4#q@BR^ZcEn%_bhV%rJ%Yo)0 zityc=Kq+nOd)(EEM`S12&}Yq`H9T#duA4|6(}NpgCc_O_1y~DLT7rWX>B0u6XP&2` zK#aEMi$3iOX@b;q3=ao0I0kC<$kiT)pI=Dea=F>VgdwY-4z4NAN>~gZ<=H#sCY$8L z-d!3IAo?gksvG23}PajPRg#a+$Z~09$wb zs$K@?@d;BXMNr5oNbqeFE>G zhBiJ{l#t|~wxZt~k{+G+6V<+k?yvOCllx7In2Y3m)Y<}^k)5CX%)x3S6hWM<@wwcE z@^ixb=t6NO^{b_ttT+tbgOZTY$s;X{xW&scF7iISaZpTUtK;a|f!OH$1ed&uRCwzi zL7KXgpP&!={muo?l-)NX#18{TMD?+ukY&dOBrTZ2VeiBzgMOe$l#?ED@GJnaJDcO6H*u>pJ{*{R*68s)%t5l2L9s%;n%}w;eMqI*#jqjQs!9F@b5kRW0ML)NJv$dz~$CFR;9FPYNV?t znylEolwk}6zLYvrb8MQ6I#F&x@x_)0k8tmVe;V4A9oIv{_*C59lsE*PxC74vt@bV? z*iZyBln_trdiAp_MA)B~EUYmo?kA)r1sr~C@LY&>ix2Wk#ZoC#GX2STcmaG7-3 zZD|>Pf$}32RSAgW#Fuvbpy?Ix`u+5E{`AApaB*ZuN9YartdIC5W(*UEU&BGGo{=wV8-I7G^39cZc&SK$LXc@-k?stwhEx%c+S*996YmdwJ|v zL-8tVbfqQ{*^|A^B%WCF{sxyjS>jGyyluZAa|%6P395sXy|F0T7)>KX<4Qe)6%_%% zh?JEFpyGbB@St@m|F|X?v9-4JLxg0Fs%OV%N3_+v;`Z<-{S8u(cj$&Y?S)SaC3 zol#nDukSO`xdq6g)J*92o67x8_qF}DFlP$5>t&TCHyvNClVBC#B%h&OZ@p$e@yI0|uRVRSz?J2jggYuJoId>CH%hJ&=!@u!C`2 zy0;=!_EqgoyH_>kQ+k!G%y_uJS+KawpqkOg?Jk}`DkwpkdP*lzk;GpWvT8G~S=|#S z2`ybSo2KVYTMcFcDbb)|iIKgM)sEGY)tOZtKuE3hPs#ejhyY;{?rAIVKuU=Hx66^56uY~Yl$49Iq|o4t^r5n4oJ%x}?i4A@;^GW-Z8bG* zZID#5y8000@xX`Nw~Gx?X2Lnv#+Qz5509xbn@(rj(X>vQ*u(>w>o4{s{y5QjJt_TS3VH=v zs(mtK zV@j?0yu}1j;ORHK`4Er_L;cl+>k084q5DIE?nqOsYdqgg@U8<=?#rE-9J(aOQV)SA zmrN>(D?T#3MAsrWm>tQ0WRFVL`)`GHvV+s(fR;0c%vM@EUgu9z!7Aok zUTZk%qQ~Ea6CN$Qw^)EArUdesE`pOgH|D#_nowCR#iXy?OGr)?n98a&nyO^0s)Vbm z*f+&qdGVW}A{7W2#Zc-vCiU{|3T#xW7@2f1wi6%Bm0MXrlt*`Fp+l0gRr7|hf)Vf) zNwmA{{b=%z4vq&B#J&;sq&Kph-K5}~x+XdgQp^He%0T>-og~#KZUII**5!yrCk3%9 zCcS-kjdnC>fk6Htc)d|wq|Lm?snE!6N`lDe%kb=x69i~jtWqHI$CI@`;H|g2*=)JD zxoL`&Y|yJBa23zp#@+WW>twdU1uS;wdN07(NAPwx^ZsN$n|ny%=jY=(?j*cmxhm#4 z?yPcL<=!K~BPCyzGq#ftwt@CarQ5d&(b6b$)rN}2$I$6M8S}2+epGSQyJKz2C2^-K zG^BC3ha@zD(Q2v29Q20v4&#-1jK$Q%!+leHO^obc@V?$*_7XO`jBKl*wPGd|lb<~WeAP|65@T=*GTF6)N6Nz`BsU5+U>KPn{ECD0W8n6b$tE6G=OM73#bL3A6;Vqt>fYt-hX5)#Wx%r)~SU3THF+ zdo-z+rJJwgQ40z@f3k*W-32ey?s1P3&aV`M%eaAp7mX@xepJ#F1)9vMKJ=@@Ka$rd ze$SD^7W6mpe;JtSpF$%j)~=k(uwiQ63$9%pWzu4e&BEA7FYrr*KEk+`)8oY~)9+U# z4hu5;l{dzHYy2yo?TJ(qzIJOex@Zng&(XBHc8+VMb&=*ds3V>Ikt}H`UEaL2eJVN0 zJe_C$hM9wvYrm!De*1SgvQcn4^f3Y*{dllE{XFF#WM5co_o@7ni!w4jJ(CkXX4xi2 ztfz2EZ9S8YPdQ-m`6+xPS{94^9mS4BwP1SV=;C5=osI*kgi8-o|4ci>UbD(ZB=C{= zdVa& zgd!j1Ebb{1ctiUV;yjFOuTsUmn>v0`#8EnuFY|2M>3+RpuZwE2|Cr%p^$noCTpr@d?~SEXg0#T%OpzAL4ab9M%N+ofH`-X z22RBnUbGxzT-3zYMAyXBBwWQ)Bt@esK-Oe`2SpYN4fz5@%Dm?vxG(K0J0<>Q1pQ4l z5nqz+V;HYc$3L9NtC zbaHZGn1VD>0$WnWH|zCRcf`pFiR+3iVGYmzGU(uy2(FE|kBKGCihu zjsV`og>B#hzLArGBN>m{dUAZCR6>h{4KQ4Xz91Z=@JhRA$`@M*&NR)xW0GxX_f5Im z?wZp!a>9wy7_r$|*o_;-4wp<6SLX#k=$J(HQw-y>akx#sYCu)sYTf0Hj$p*a}DG(u*Iu+ zfwo?McwSR)QYq(G-OCb*WkR`G-ZL=c-sIxbrRinN;d0vRJRg9rabJGwT8&-IEF0K^o&DEh$vj@Jhws6nss7G$SLa+) zUN0jjlClO}7k6toSv?thGh)enwVloup60=^%V>zGvCF7;DYi(bV$@Ii)RR>h)`q-O zP)#GA7`e%!ebI^(AAje^-1wLTz;u0O{VDHHP9c%Gx5O@tcsYVSLSRx|KNmkY04wS< zissy3=cSYy|0fiUUm|cKP}cOC_patWtqgYrdd9nrc2kd$Eegp#hj!6sS@=XJ3wF1l z3GIw=uc4^ubDvuvXtq8@v#YomUzYP7;Y3CH;{1A{%Fcspl#`8cdaurJ(;JPmNWx;* z52`#85@|z%dDh@re99JMb&5<3>j!jcf;(aN;UBhNq%yjYBEhIESwTUe$v>vnXBJh@`)t2*GpqC^V`p*aBc7%dR}>u0-|BYitKgS? z_A9vmy~||MaX1N3#b%Y(iQ^}W8D;;IqSMgZzK>G?z&AVaGQ(XyG@-GBB}#WHN#g<< zlmDdfb?c!v=yXU|FjC|0U)ssySka7Z>epnls2bO{+Fm70obW-6UZFH#k0dwlsyaR* z{n|7o+awbsD~)pK9$0|R^WnY7rf&uvN(gHzP(B!GF<806Q9fS3dVB36e)OhZJ*dy7N4iiNdX zGt*%fEau3dkKG0BpFo~X+gsxM1?#uE!IJwZ(m(V>z-WniOCXABCRI?s4{wXc3YB={ zX!P7jw3WN5n6`|psV$Jd7f|~A`sn@8B%{CF{Z@MdP*3+&0=u<|)SUNZnOBv!zh2!Z zuaJ&tvt>V(rk914E$dPjsYXDk zK`viJ$j5RrmKu9eOw(jGRZ<8GE|;W&-&Lz4sh-ujw3!UDwMuqU)%KZ3KJ<|$!1_eA zmuOXOWCNCH`PMyt$A-P?H+lJ~Mr@Z*Nz*9*vYYN+hMG2%%-Za?EexfDDd0L?ky{L5 zdLXeh8D6wOOb!pTAT%u>1)xKS`CdX*GfTgo8OrWJ)~Uds#_ z2RpqS&Enx~el(jAlp5*g*8^j$l;$fr9PF{#9p-7R1_()OFxize(ug>ixd+FSMu@O7 z0&9P`Z6j*QWDkvTx~jQbP@A)#XDouszGv?69!G2_4Arq3{ZdY4ixCW1F)#~70tqH! zaTYE9HaI$9-5}3rn1%;ovFu`P3&HrHOTLsKZNIh zW&mb?ysgc9v&e6&yIXi&O#-)Sy&4^XZnIO8(2Q^9hKFty9oi^nraDnQoqEK8N)z1?SXki)w}GF2~g>yS7* zi+iznhvE*dKUqJXQOs1LQ>sqFej ze%uk+(|6`bk9v}4AZEqnldiB1A-!5#2-dS2e$BiujxFKC52dU^KN%)vStnz)?z=L5 z@5P+EvI2pM6=G26ntPWTocKQ_8OJTW$>;;0Z zXPb1sTUJAOr6`nh`jQbTvlYNXB(`8|9;M3n&4D9*x~jahaRxXC3%hbkCe|_Z(x*XA z!5C2e0czQO<;id`QHq$~M3&$ahtPg~RV=xKiAXKOPvc>1QoaYjA5b~#@xr6pw)hPDDkltnE1rB(Rp&ZFMx?OO)8=+ zOp8ccE;0-{jHk!--Z@IKvhk~9d4^GWbA~*m1D~oil2ncLWOT>r4O$DSmI&05K0luv zfKQO@sxI@-Y${9Za~lp%kXx3EtKlLX(q7U&E|oYkz=TBYbVpm^r7<)SrNYc3D5cYh z)gAJ%$tx3-gOZ&-S(Lv}o`r4bAj{B5Q3i3W{7D z6V(FajB+!SQtOY362Es}+SXk7Pj5ddknqUEg5B77U@^@Fop`a87Y&_=3UHt?-%3Tc zqsaN>r&=?eS@;TJn^&QxoV@PsDVu$^3z$c>R0FHmyHvo@)5fgGc8hbX74KfC*#b(i zJ_@pJ?OE>1*J;M=9@bKYD8}7FGZAph%_D5=x#J_x>fl7l(Xw# z{puDbAa34Dqaox-P!bh-*xX`fxz$JVcz~41Yv|$Nfk&Y%ETIOkBXYJ4HApO7({?$K zJ^M+!I{~!rh_F!H8JCs2k^TBY=2-q(8uY^ks3!N|(jFkFBj-z(&y4sRv!Za;$qrse z6{*wLmsRD90@qW@lPBonO&Ymb9$_T&>47&XU835cI;Dbx((z5G@SM0o@Hf1fmMiR1 z!Z`dyZL_NWh_rV=M462GBVOjQiQ3aW6#YA9Vk>F{cXaF1l#>&S1Ow%B3z~*+ zkfmb17A#7fB#)JgrO%-hvu)ihL_?bzKjG5bm}$&bI`0=h&(a4K18SjtZXTHZ0 zJX1W6PYJmr91O)Vb;hJp9|Uv1Vr1w3>Kqs?21bA$HR*PmL+d+DL$$YMlIk65(G0ta zqe-lmw6bstxmgN9TgsKoJ4fWx+QBSOa$3u&mOWIb)QM1REZaY*5{)jX_$bxsnLz4N zHpN`UuZf8B%Fu@+h8+p)o}KmcZIhZ7wm^3R2Yk3_(a^cz(9CG8k-0okzAxr-@E=f? zrm(A8p)RPd6G#ulju`ehuC%`vc8U6_Y_j;%JrD6AI3)0~Z4;h9ZFpEwmw^cP+pp#w z7BN1UkXaz@hY)Zv>MhCF@FYh+jp+kCXL9+nTMTnj^l2OV0E;JQI0Xh>dD4AMme^+1 zJI%yGXi6SzN*>zA!&87|`m~pAhen++3ogN?kPwRo9QPw+PDQVWG0nq6iiPB9gKlP$ zgDFIhUxFzPq)aid?%xt`iablwoCQ^F+CJ#+)6zSgR8R>Rz{^f9iEdrre4kzJMEqS^ zlX5sN>!3t`Br{2oPRj#w%Pi`)w^kOR2aORPT*y1nWKD7<{v;gVB{T|e#{mn^qD|g; zUI3}pSR&dp7@Oqe@azPwKP0IQ#>e-WS7nxU-$=@BBV^d? z(CvsrwXsCqjV@R+c2n$To;J1KX6IPA~{0xc$`H0_P4(1Kyeb>X*y z!opPXea$*bO?+L9WF75{$w@7nsMnmeMoYoogXw{s+w~t9!mkT+A}VNP4BB}1KJz#+Ji zlPY9goZkIzruXBvhFkBV!`u>qPF8nObnf?84DjeeqtRRGS?`l3LSwjBV=a9y`E6)E z>WgH_`OW*Hb)V(%f%bWQV;3v?ch9Qx_=`BpANWN+dIo>Gfam#%?%Y?n6>#v3d$t{6 z?93Rsl8hb0XicA}{@cb?5TkMl2Ie>@$W6GvBhOIpd(9@UQdXbs_*7<|7NI5w&|9&(owuxye;0kk+tR;I9#Trjin;)QEhn-A3_p||B1NqC#wK_F5 zG(VB@^WvP6#UnioUu6;;!|o-6Vk!tQbBHVi#Jo74yPbqqtr~91*ZnLJo|h7;-Ik8e z&sXPDSuWiQ-LR)}nvXVu&Kj|)*0x$7BvWTSUJK@B_BrtS^u3Z7h?nJZmRW>I&DR1H z=b>MlKKJNiNQ(_e@?wjNk~Ss|1;ptH&r zk8kP?h(5|X@)s5pU83)@rA>ibk6U`N>WvA8;4xd&(*%{&CvW);A69eUI~uvvG6Y zP?FwqWB(Z5W=ito(?B!^I>8~{pXr&C%PWpZ=LZIHt=`Q!%KJ$nVMfuZi9K*EEVW_b zP@2*y=0f`H_2NU9)_2LB&v?}XnWQ&gvhn&3m=27nY4(CW)2(mjBBj#^PAX&StR*ke zh+qD!zbNZ%+|^n5`EG0Ly_dY`nOkFircA<8*RyLAD_6BnK8&oAga5e)FVf@M{K;f* zp~J=@b1NH~0-MYN3KaA$;nS1GX8U!1=DDY(#ohUz2l8i_3Y&UD5`B-%rt|Qt&EAh^ z#W^>HU%qTIfz-IKjM>I0x63q4)7e5?K3$Rx2n~gP*Wf2(Rkp{xa~~mRSf{S8!YOT_ zXAf}|C{I0<@2HB_D8AI~#(F45mS3f6ZmN>W7kHHkncl1y?2Q|v>}T-PkF^4!r{9;dY3txH6}cB4{!VAzsV#O(Si{_hNmqH(S$%2kxy|({ZP#*Q zB=sB3I=kOA*)qZH!dG+mz3tN7zp3hw*Bo`xmDVlGm#!R}ibqLG>g@;mMpits&p`VD zyWLM4wu=2@ZzW>G3xW4r-aKptIAOJ4j92lyknQ%(0zrY-mKQWtRf3b6`o-fqfm=~#=te2GT zEYVs3DC-3tT7rxE!|M%egeU0tC`=lArvw3eG?z z^sI$s{r!X0#_=QB8}hN=H`F7+`ZZ@j&&P6^FaujfwwjC8j?HGBR&!XDnyFEY9tje9 z*YL*>AQ}8>bz}M2Dh=Iv=;5Yy zrWiX3YCl#ikl=I-84vgac_g1dZS6q9sVaI|J4s_!+YTEX^H|@cK@10@IH13!NS`G~ zMHwb9YbrP{hXyN8iN0-XZ*3KM-C(E}KREI;_Gf1Qt1!OBo2Fv9%rZ4$l1q|o5<{X* zqIN^krbaJt#CTu{4bz4MF#DAyC|Hyd#e_Vbo7z@JNn4&=fI7&+f-aQQIPbu(D`!siv3 zEsNDQY-Q(g{A9U^fPaJY_|bC)1f9d?WkZb-L5lrb-3hvtVBjk?*C0XLI(-oQ5YYiL2EBX?_vtCiSUiZ?L$v_IOyPKUueQU^o05v>320e?@4$o7ey$SC9b&#p( zoLJS?yYV?U`cRF_?x;7vCG+Kj4L~W;Z`(}Xo$`_1ZoiQo*$IoAUb{h;Rz07`qZkJN z$5bEc)(tk#le1Uwek-z-0H~X!+hpd)IR#2}-=lqe1FG%sL7#N7!f{V$=jz9jahqw5 zRf$~9zDwQ#SM^D;Urd1X%+0LR4<*`PLUHl|xGBejw*(4#=-om7W~7B~}r zS94aa&-P4T%{N-$qH3#hi$9$S>N-2$fuO6|@n7TUNNf}X6+zS%{6OMVSN zG4=VuHm}2V$FqG(>t@_b$Oq%Cw^ z8V>)e|0!f^NeWOJ#hEm3&y(G~a#`>+T!5Mn^4$#yA&5NAqIM`xD?qc~T_MiaM+a>T|I zgTlLHwx)2pr(6-s%A#Ehp~n}alpmKr({&(({Ks7ytu-eNu>$j1 z_@g&pgGQ{3QY}TuWQf%E*Y9!rK!&F%eFqsTa4>S&O^T2R#zkfC-ogKA+lH)wd0`gH~q1EQj9M=U-Apan|<*WD6Kd% z8O$4+$79Bcq$#A6c-(yFuQN=3%?4E_&Ui*n*^|vC?tRJErb}uMu>R7}lLX$wmh_Mu zYmr|92d&rwzPOX2#54JLwvfW>MAzwciRctoi$CrT<#EshR|sGa3vVMjD0u=0G3;P> zjh_Ha9)T)N;huH#V2yc?3KRaM!>V_f3^9xpJ5E4jqC`6RN5)<<`nm`&Kw`2}^h{aa z*6(%NUCctZg7xeeLPoYDNBa3lCf5`k3m|4vDq48;P-`_(9ELIyf}Dd8)M+btIZ1DI zr^2NwtGEy$EP|t`b{-1kj;(cQnbzo+QBkZwOGNq{_bHvv<(7pdi`Vm4L8d|5{=xmm z-Fn!HKIqi{HXVgpsM{Vd|O#4Fi|qntEIP!M)+s#av+w>ICjvqLjC!0!~(%9e2h;C{R49L%3#79s!gB65hh3W2toUB(bQq&ZN7;MgUI% zlM*_EgnV6FgUAEZ15#la7qjZ-SBuG6zq^5N3)&#S-0=a{P5b?rh}A8GN_E8WQg0#6 zw?E8^HB#3y^|Pa^r0cHB>?<%iMFZp_7{+9zD+3NOa&y*t9J}hcD!ID5GTUdEY<5m` zS`2qqo)de~_`3OfJOs+xm#n?Rq39P5B7&MH5KG}Mmld4JG{lI3(-_`HB8bp@4f^V_ zUp={&Oj9ej3DQknPfnh!O2C1;I&t)StD6kHLr&l4u4sSb2@JC!s%v6_EE#Z9}(;eMqsJ4*yO^&GAX7YIK{sip<@oPt~Lb zN8KLs2ruhrXJ-PuN0Nz?_bO7GYw8of(`s|4P3M@K-Ilz~a=!k@pHd*Ugi5kYYP9-a)?1=GppHG*6+7+DzHu2`7jBg-(m$V;C*M%NPzribEIwxQj`>4JwEB-Uq6H7 z#kko&PzVm|2dCjZBGwwFzc%|=f7d^ zbpTf^NPdE>^E~!@9isEjIkd-C$8tYfnBZ*sDtd7j8je=IdQnX%#>bq>pG7tMq2N}@ z!C{~mNbahR2vhY`Oa@Dq?nOaqDoaaRU?~8`aOT{Jh$g(l!s!0w>=AuCw7BDFI)scl zPbWr$b(w3AKAPNCuc?k@O+6Q$prThoGHlz zax)F*@LS8f!Q~V#FLK2pL75UF6h0on+U3s_rW2ZTGyh?~@uc3F&6*Rw`7y!CnPYp8 zmHqb6(`BPk^NV)%{J5cnWA=>@vPIZ+F+++Vi_`QruNr4kQ$UZ?$RB z=}}Hm$3HVteNdI+&WB+Ehmv`o=V2z}VSqyU-=o~ZSH+`gl5LnReM`3rk`AfBm!U$G zMXE%kO2L}YP!86lg2N=pK@|@zx)3F!RAVEK9w`oeUrDCFx8O@=5Qwuf@bR`Ir^mx% zE(II-IN8e?+`Y>u-Fw9QYd{aJ|5AMJK&GdVoK;vQg#i|{EVRTJ<)Gy?Q)YwMq6@ey zfV;~EJ)LTy+W$m#S0HiPd-rE0Ib9wkDVP|h>$G;1M38fQBG{j8u_@9451>nm=DwC= zMc=cv3KsSqbMIV17(x1a9la1&AUVvxP)Qqx z^7@s+()AhxN7Oi-ZQ7;eVILkblIii0FF!~^(;hzfx8&7gz^@sW(HZ7$zO1HghjcxR zrW)eJs{_CDWF0u$cK0c;zp35J4g|b@RYu{xPgZ$0lQSnU+ZgI&?4b}HGoDNt{Eaz* zY~Q?aV0G*RlKhu&Pf&YB)r9@0J8yl}F?1Gs(^_2YhP5cf$FV3x@UD2s$+Rv#ql^s@ zCXl;#q=7`0r7HPtO{Sif;uj?vV2YF+n{1Pheduxe9Xct7kb!X%l$(7(vm{<=KnM?% zm9eSB-b*+Zn!7|^KN{iKuJMd*{CYR;j3BbgRhNXZNiRI^{17wpHa1%3V=wyI)-Hyl zbe1VsWG!aa#*5;5T#Iggf%tRH7o%T%&kbM-Z^5blFUtp^9N_Mix8ws7wi)BbV?ZP?fVo&+r+WTVcaAD^EQ)m)ctdB=<@l-m=EW z8_jhao7!oG2oJOYU_Gp7+J#iFNnAugd(ILK_w|e3^JD5wA?qKLxRw4w;@U_D&o0Ew zms7vZvgsx6+K7gTuZ;BUFe_&^7YAQ2X_Cj`Q3Pv+O`xQ2y*+3}(FJ`Hw-$%iGCXyz zB}T84+Mk(vI4c>k+++BpJjE$gMQqUtg}-6Bb(uLK@;GIgap<&6{khz<{U})ZX2svt z7Ma~>?*iVzY_!_HEqMfYgB3oS8+@WiIqRu5#OpjA-io6T)x! z->a+^r7mDqm-wQq2@3s?dQ9n-lh|vH#=GlxQg*>UREDM;x*s`p(z_6}T$UZ>g056t zi=++}kgi4SZW99c6cx8h+Eb0J?qw9BnW%)gDKVFA=EDK$RUFtX4<^R5w z1p4}}D(xBN8?=F~Ci&hwzI9hsg&uSDXmbgwPsFp0B3sx>1KMO5VSngc7LwES$ zE(b?Ho(zA4bf;dZs_0|^~;X<8|iaz6S85S8FC#HD#i-w(!9ndgFbc?1L z3H2#*eLPUhHvMe()awYs-)FNtd8Q-9z{QP-DTY_V%2jcRi=rokP|7V6fpejT6Uf#A za~`wJEvvK5!9&JLgrO5doXsiB`IjnX!NW&gzToqRWcZAdQFT+qo?ZHK{Rns z+v2Tr{xZlaWi%k_@P4F$`$T+M!ns>1;J_q?ZOHTq2k$8}>{2{3`ibEpU(y^|Mr;;I z$z_Bz-N{=}DCPtrF*Nk0ED1nhIQvlg0}3))l4?4kwm+o`=^09Fbi_qoE<;8y*%ZMI zER(Hu1*Srv%<>&TilKXlJ~&@d5S9v`X_nhGI2)U;rmCz8gD=U8|2s6jLDx~t4uIp(gLluD8WKc9mf1Tfe6$(!eJL1MFSZWqe)?!@}&ya5DW5n2l@Rua~dEu7M* zU9#bo{oVYe>|4!T`Ik$+vf+xG@EU)Hg-ngRh5we)m}}syzx@aHkToV#bEJhM@`%>L|Tk+W5zt6*>X=u!z+p&^K{KGN{dcC3D}&wD`m5FqyKrVBz-i zg?L`z_4|wV+o4A7Ccu3YN#UY2JcaS3^L~FjPb8I)5G|gE4g1Gs^_bSE=@cUom_< z-Z&@VOYgu)IzM|#o&cK8z$*?YMSkzzH878pR8{%8U8bZADR(xaB=3TpnbWUtDb%Mqye!Y) zOXZRWzyIwR>5yIFjgh<2??St!{tKa}O6dKB-OOn->XA<8!G ztcFM7)Ds$R1E83{EQ+5`zx#4i)=H#+Oqrb8d5MGmX-+DH-@?<~+kN!ngoDLz>wCMI ze0b!!57gof{xg2J#GPc%3tWO`Zz~O{jbW=X;7Lz^dvga9qz<9;H@0Rdj%MH0P*S_% z+k-oPiPaANPj{Kl--4wwEA~)fUrP4xAJY6DZ)r)^);`qUnD4K0ZMhjdju57oEVyz4 z$7GzI7(w`pz>&&2D6cZcA)}(+8HI^PwQtr@)NmyqM3<8ZlB64~w)PDU4s2^8&IVQ{0`I}=3m zS+z`eJT@2?5EA*C0$+Ypa)lu~m9jfuC3qk2lb8#s`(M;X)z`Qv`RS7R39~>AvoflD z_mBs6jRbKN(=RMh9=5!y08HeC6@f-4X@Cur5$?;Bjm}PY6JM&F&N^dH-A9G16V7uk z>Q&sWDZPW2`QZB~OaY65t`JGk}d>g`M%R3t0z6I~xpF=`xS8P3Cs|K<*Lq&mvwv%1b;#4|Hq|D{c7uDO2%Bf!A@JuS(`sc4r{T zsx!$dzXM|q`lJrt2HpV*KR&BNK*VH8ExojViK+ zmw{C8q#w_hp9$4B&WOKacjg%4a=&VH1fpU++)RJ)zD+PF?YZz9x;!T8gY(l-u?luK z^hH-P=#_i0jI!;*{#l}9HrdMYO|l2uAm9%)FTs)F{{#jC{$m&Ue}T&Wa{VAwGZSYk zM^^{ue{uf47}-Hsg2Mm27*w6jjNMEu&0OVGAa`wzEL=$05m|&?OdtS1QXV#LW*$y< zZb-@BM*bEt0f9hf04Em@*I(G5nVmWW2FT3H#sT2qgpl8i9Hq>xEG!}PHx71Y9&T24 zNG)jyYR$?-*xtg{jPx(;45E?9KO{jWZVqN1HZBfGo18#qAS)Lu8-!TL4TLlY0CJG> zumhR7xd5y@5bE1sAqXYS3`qJ9M(r=M@V`KUfd4@f{9E^5693z9(tkVyVY-PJxtRT} z@PD^o#m(6D9~z;kwAkNTe|-o6;6bib9VDg2+cohnwy82oBglLA?G~Y%m8+F4mQXDvM~d>|GJ!mjf0uoeKy#Lc>kYz9IOC{ zLTrB(XNMTb%?W`L0wEC$34Dn85P!0=L)!l9PaqG(cR&EdPuy&*%n;rF4;cklO4IzX6 zS2#i@pO^;3xWAG5-&5}Ychf&M;D3S(^%BSJzp>RF3e_%8m@6dUsZtn{*bY!Fj?Da8dM0xfylVmNc&GHNOQSEKU^U zRip*XNq8OJ+6X}*&Dm`sdb6z9IryI8Ct-4}5`0h=CWq=*8PKz!)RZsZ>|!jgO+^;tF*L{L z2BQp#5i3{tpJ~zgd?+$lC!VFI(BVnmLpHeXDUb6EpiOj>z(_IuHye4;v)TNdIe# zNzbfPUnCzD@w-3i?Og3&52)pn*rhX*+3DDsLR$E>=~0?sny&m-$w4?}UB!x@FT|D5 z%gPv!*Yx^F>5m|Lj4}RZ)-&iVfTurt`hbnCfxb*qP;mO1n@$-|{(>v?`bV%==q+o~ z=V1No7LUaY4_h-f{5wjr@b5O3T90T}y*JG7ru)`qLt_bea1w>#K1W_|u)3Z+^mp{i z*j&8g`@h#u z3F&#}cko9bJ%v+@>umCSTGvQX-#{_c2{})dueB?Kqp_^_Kf&BPbV<>tuU&f({QL(A zYJO!VjniX%CNb5~Pc04i6K7$K`wzdhs8y0j#N+$yK>TH&4XOt}njVX(v`$B9yY3dD zfbxJCE{n~@AAAOW7g{f?IPb{3?N1ZEZqZFBmTQNedM2$8mU*nb`~%Ex(=^nDYK`&} zVOlA=gF!1SWtFI196oRX$KLN=4FapPV}%&u^PmuMNdFgacOBM7xGo61#ogWAB}j4C z;_mM5?(VLoxVt;WAwY3=cPT}R1!>vz?4En>-Luc#{c9n~lVm2J%{P!_=J&p_p`4j1 zn|p+Gk;0+j&+JD-P(;tOYl;!q5KfS?G(X-sKW@rF@=J+SA&qep_luqI<}qyH5cbmw zRc}DIsSR*@oQLx6<@6Oga)B(D6m&lH@wOqdLhg#z3ej?W3>znqVkQWlA)Fo-wV5{%u%Dg*^{C|-y}3L$QccL427en5v8 z=Z&roK`vPe=fb8F?~UDsaI5Lcc&&$~nbOwDK(M@B?SHvJtPrufr)s-gS!u|uiUT~; zKPZ3%_#Z{5phf0~Y*%yhNu~MQklCPcz|eIrh%PV2+mZd!fi!Z_OXtXn9q_&o>x1iz z?BbanS4Q*zU|yK0ynGvo9GDE*t|isqwq94yLUA+MA7?*Ko0;uPxbA(}Ie9YV$xy3+ zf~RTLiKaURAQG5y4(c!^&SS{~D5VfV0o!J+S<2E8Zrmf*pHx4D8GoGV!#Npn#*1p! zjJih7;y}%Ux*xngL+)+#=b8Nqi)cb0Xh)oxm$a)9XT*(pS8?cvGMd)=Y>c#$jS`n! zKe9FBMEgT9^wXVl_zno<48!5QD@$lo6?@fqSD;x8`dl95qOEpKSgQ6vnwSHdIVaQyU1n)J@y zXUS=n_kHOdRdAI`Am~rTtg!kfIdqBK1E4fow6(s_Kk=4Kj^C02R)<&ayx&=?ZIog_ z$~$)|e9Qz^KrYd^MxhZ|caL;W1o<7d6TvYeqtb)MbjEh8z)YDiW3Y}&(neIlm(;fG z)fjiB7p^|!r!lSKF`_mMV>ox?GD0iqwsS?&kU@3T%-Li1TlM25==;j{Fn)HfIfy7U5^ou!%AyO6LEoSvN ziLdoUWB8@R$2_p;53?)_QsQfV#Quu8M+`++em){GbhBp6sOly8U4-pvLgsV|S_-O> zjNJo?W=w;I*P)hcu}X|@&^y#H%jn0V$8e=0T((mdog@vZTty`TKGN_lHJ!48g=lgo zgGT$;jZvWS-7|p<(Toa&ntJ8O;^}kbLzi|`v&q@-UiSq4neeQ!;^~8x{aORpYqrCP zH|Q=Y`s}Ilg@R`Sz735Ze#hF^Yg7~&>LYuZUX!Mxt;-_2ciaSnvOpz#ZD#$ZVu?`u zB=_8Zq~bwkLJK1G)J`c%*7SMu*F~g=9kEH#4RURu1?tDms+~6?WgQi}x1`!=V)ApkchgjfiCcP_5cjwc}>fhNO$- zwwM_@XMCzRHGXIiY9v+VYY?jtmfC$P^f|78-Duemz6?&(Anx$u^lGIeE%Nv*`t?^Z zZg0!Hb(rlu3ahB_r4rq#6B=ZFUYvPK$dQ=-*Ku>4uS%JFvW7}mG(iV$L7@U+HTPV+ z@orqIs0D6H8&N3bl(${sEA!9p%m&hWXL|RYWbnR&OjL+EL&`rW`yh@dIU-=FZPOT5tMq`k!PTnlIGa6a}>c!oF$zcB*RNR3@NK z$gD2Y1N%Bd1!UP%w;L*f<#CQJRwmqu2-@K>|hfZXEJg#>f#-t5*n zq-BhU4}8J#!IY+Gt1pt@@<~b{!}m)=<0Euhy;`~36#TK$OmBI4sD#3H9~mBdBpk?A z=Z0+|IWY?(cuo+-SlOt0kggG4qp5aauVeTQ$fC}Mhv?En`=cQ>GLl)|KIWsHq}A-p z=qA?xNXq_1H%9rrq!M>DMc`L&a6Sidi0YCO2&!Iu^Hqr_{M8$KOSC*@ao_U0bpNfJ zH=LIw>axWJlLxy`%nVkJHHOVc2BA+um22e1^4hVzo;;Tz z!@~Eo4kgCB(2h+7Y@@qxyD%T1?r5zJNc!R0)@tU8Nu>2mzD-Cd|0raAaUH|UsuY0o zqF>x+w;(<$6wg4%A0wnfaFvTX9#Kv1-eDV^DxP!3@6OcQ%Ms+# z1_^|JA3BBi$BzzlOapQGR#8t794n+>T~(S~hti*gkq$Jx5lG|Fw2B6f!F|)g54FlE zs}2C@`e@%`5Kk$e41D&6`9oDzsEI(HM0w=#w!>JIn5cq-;6cpcLhLxG0e5K2EcUxa z_ctlgRtr2G$L80qw|6Xc%p1laQ8Ys3FE?0P*<~L}l1W0FC^Cid4rPCNrSF9oO8Hnl z<4tO3Ye(9phWM;{{FDns?2p(L(+Y!8=J>;kaFEk@h4eiAK7Gg)B{!Bth{b~MZFn18 zJoM-H3)a!;!&Sy62Q7d4a*3ZMAbI~f^Xjg=%y+9Et716cUanc!yk*>a?nf(uOdSTa zELr!KaOo&6{E7syFleoj=<%vyBz_}2K06w<>myC2PCdVVE`2kedZA*K9vmB$2uO z(u6M&F5>gE^?T)f#<9iK{e5-rB^-U;MFGag_q}LdV2ubpDNQj;!e@WHUHQjP&LvK6 zo_dSfn)u~Q;Yf>bi?*~HQsEm6T#?k_hnbQ@T13wI{v$JWWf_c^a@%5RU2f$`y*bjgth6;E0*v(t@KhH$p`r}K;f9rl|e+j5!APG12XuZ6RB{TRVX?J=xoYn8Kpp@4+m<+a9kQXt1+j??lyGrf_u z%uPn|(Q+NbU~QVlEgpb}8S@R(BKKe!UxV!gIDx@M`Tk6YhQ6y#I#arkv^HdfgPEbouin!&L%ZZTgZ-71=_s7;apDy{)Y4g9JAelNt!shA6kl?mzUgD zo1}uWNSTT;E+$$%R$zn|<>)%VwHdcVwZGr+(Ij*dw#3=Nt|r#i<#}-tKg`J%8jriFN@leRNs^gw@3{$znq*X?{8g3`K;mWj;k}K);kQn$tMpK(d08#Qgb^p> z<3?36zm%4V@xs?MK`3kkwMDdkr_X8%Y7R9EJR{d>zZEvmTJG1&Uw&nG?zJ*(I=M?n z)>aL*WsAl-t1094tSf0I>=4n^j4IY{(LjPU6Kd?s!!uWq>Nj#jEHXCzKbYjp>99;(_wVaG#wqr0&s0(tNcnekT5)bD(mtVl*J@Vtx#hUA7qOMDE3X13@3 zDV5r%veU+l>`EHas-J&k##I-e-^|aqUcOnk6M{Ly|IgIw%iElE4i&jyCui+JlLfNxQ=w>Tcy4O@a&p8%`dwVSy&uvV__x zIg#NWpgkzpUmjIVeLshjM(y;w5bUorLIjIQCC`No5Tm4uk9Qf~c2Jr22W$D?pgWKuj^Y(uuQc4ZCR?{kpU4AHq#F}}KIFp%U%XDdW! zKOL}hr$;z?>+aK-`;xte3k}^_B><|q0bBh@=SMRr zN?H8k_<3nBQ-A0~y*WfPyhFNpf^QZ0Q8s1WIbmVFVVCzBFJ8`jvDd}#d*_VzlKFk| zMtkRSS>-0*()!kNPa;HpnPBZH%^1wGQ`=}nE z`W$7W&L?{{HctSVf4=5%!4ec&fjan`0B-hIWLOzpun^2(@m;c*_O%{q>HgkNuYJa_ zz3Csxrf5BZ$f`)8T1?WhqRum>rFc*k(_-Me2j<|r(uv{-MHxG<>Qdz$yWiJ=+~4I{ z$27hXX`Q?3mraV6erbUXL|fmwvYD9}!tUlLx=1;8*is}YAWty+eE7SxDUs7qoZw5^ zsOf??ybV%{6snCpWrE29i1R#2ZvOKSbDkmMu;M~z8mEvV0pVw}WKNjRW-vDQDS`W% z**pG$LP`@p%@$~z?pgWVXl+Sf%MWAAOQtGH6xTvJ2}_1{hqT96nRR)o6Uw&R%`+r+ z{cw(_2|441qL2&3xddQe0kPi;PnF~IhZXaOQKq7)@o3HLhrRJiLRAvly7z%j`_@uZ zBjAa|4xaC*;HiI3H2T@Z&^|T?1avh^BN^X0a|1QXZM$caC}s${ekP&WIv_vcWM@~9 zDfvC%DE%~GJFl%9DqWW9GCFi>J*^U?dvEbHWxAB{1Gn;T%WJ1rYJU7rh%C zOZ=O|h!@4sUpV*l)-H)LbI*t)e`olVdk-V8ooYJ8oMJe+v}%&BSk`plDw1PSw>UQo z3ivAr5nMa__iM6K<}z=yXvk8Q^{M8kGndI3(rdWNaV2O_+Q}1yNma~SFA=DSe=2Nh zV|X1Ve{6Bh$$pQ5v`s1cZu6DhTo}ztHp!Y!|3eB@QK)7-u{;BXgIbYkEUT-1ZGXnu zoSw=vY+7_11j8tD;ytQHtL#M9=YC~L2?7t7V@ol|`k^g2g9uGueG5hv?G*%Weq4J< zF(yVw*Ou1T*qrL>0UIOz1EwaFRxA{He&i(}z@43kf4(YZlW|m2ibSC<_J~bPrmi~r zEuWaEJ;mvJ%CBaJqg|$|>Ma^1s@?P?ljos<=IZKLP4s_g{fzDmzl7a+09hI5FT+v#%CoD$xrZkV*?>^JP?oXc0 zY?@SN?IXf?Vu-k(m>{g4r<%|DVUV)goYD1e=pqSbuo`QLP{%Eh5kE3e=$J85P@hdZ zW>QVnnG|5r$DW=)9G`7UbNHEBqEBLlV`A$VvP~}9nqddcyh}EtL>L`O1Z>WKF+C|NLJ)2Y3I8nKleE?t`?JKX;U-#h@)I$*Cfp;kN2xcQUxl=$LPr!hBCN-B_xo$OzLbw){=h%Vg>Sf6 zu1ujq(U3ei;zq!`Lec|~vm|YZhzV}AND81R;DZYQi!zhq58=d~0MHdLng>cYof3dG z6g_N=cJK_qyM;)^R*v;1PbWu-BA+n98+4&Uk|cs2Mw1?Xo>&D$9%^@fa3NBsi!v5K zlFl8trN9f(hNsMEC`6DVSCkNd!X36Qr5)4;+Tuld!;g&v44=W#b0AEa^}~6fZ;b%h z)o2xi5IQ*2DCFt84Be3hIi|m$hhZvY}WZPldL|xEV^b70l4g3_6wbJP$QaqXgR9| z=9aP(zFxEkKa+e1ViJ9o;wox)ur2z>9v^Ub_+dh*Gvm;q5#rWUJH{Kfc4&bg{b|sk zk>J+RT2(0AZ%+y+JU{>xcJ0A+l+s7-AOoKx7yU#Y_~B{z8jUpABN}z+8vPxrgW-Bu z+&SkLi2zaurDHfh8tFcWZYu_aw-o`h>V&;@NmLpjMdKbMMW=LTJ+K6N72&T?I))%e zGduVHLJ@#RrF##rBPs}mMc3O`ir(BK2mT}~h)jr{9iW`pyutOxx@{ox8Ze7?xUmBE z4<1I(4q-;m4$>Smdy`N^vkq7uD|n|I?iS(Sk~T`NBeIGj9w>Ta+*+)~f)E5EIuUiz zjUpVPyLqodenvM8azr-_8>MsaAp=)USl_U371lyPIIZ*zgPTO}@Us+skhA3A)IXGc zW48g`A8#SO(Qm~;-OaF%E?cOq^xgZEYcU|Uo_G-a7~~DYK}93tEr&Put=n2j4+1Q2 z;Kv5?KZu4}o`YX*U=Fm1PzMcx4g1W;*gQy1lqCBgClKuc_YKNH&|r78G;bi{H6!aV z8|cF=KM3vC514lYc_}V{@`@f5o`e>3u!d4V$0`a-B%;2j2HbUj3F=pTf8woQ>=&@h z`!j;?{(>vKcn&*TxG4PoRq_3j$^9h+lP^G&Ht)|kcp8nu9aR5Z$i)Gn_fRRMjGleW^IZtknQq+!G?yxWaig%Xh}BSfB5`?FGBCBP&1A^6*g+pQc?18#r`Ap_`IFMf3JFszP^ zB3NQ=kgmcWfJ9O-G(Q54y+LF@{{uFO8wekedjo{$#@N5ZqvpX^O$qADW5OB{ zu_P^;Q)9?wHOSJvVxGiH<<+cAr71I93h+oB->vpvq?mN~m&%0$#u(>*kH^%0){bM- z<&}jxkN_weADiuy$6q)iS$RcI92rQRye_ zLL%$a`nr-{(Jfri-2M7v92}M}eO-pYtRzCFV0pqKSE4EVvl={n`@Gfpf##eeHG9>&Zbv} zt!gEQ>nlnQlv<6eK&=&qDSOtmdryoE#%3uESA@Hcrdh~*bR|~~dYF8?ydsS@O`5cG z>w@&Kloi*H0iT@d!<0SXQjvh#ms9k6LEB?p^<@Q4MBg@5D7U;G7O2hEF#J2U;_pX2Ngs$ z$gen9t}FF-VlkyVT#+|&up<*}{)8GvI7GOMlheC5qGnBh^R!-*ApU68q2K4{`W!fM z{7TPl7UkQK?Ym5ETixD7)RwTU0uHf(sVCPK5)irpJ~-!Kd}mcTs@h&?`*m7tyIXiu z>sDD%_*=giIsOw8W2KNgr=j-N%*~?G`UyW81Mdovx8o$QZ#|K|E z=iXJH@SpB#qu2Kqo~BX?*Yh+8KNogOUkM3#X-|((&UWXnx2sHu?xS7N;667vcq{W^ zT#aTbkKw9L&QGbFSnqd!b~BRBJ9Zsm_6!FGk~pnIKN@WtjUYj%e!(#q$hu&RCR0({NXpdlweHoo@C$gFziqF@dekqz--SHQx^Ot=AhvKjRqKa#Tot# zy!UT4=K8UJL?p=b&}k|S{)RUrCWUvnbpN$3hj5j~FcG-Af9wxwaVBmk7L10$6)`6p z^>r-;P$T)`+D&XJCN(49R{p&}`Ca}k{9w8&s=&MBup8Q_Ht;Rrx;)(iQ%mq=@1ez!hLK3= zCry>ala<&Pr*E@@elu=PJr9>{m0zO@nSQD{jA8mRtfTkIN=upzXd5$eRKKjfc(W8A zx|`XX2`-*6d zWJ`03L(6I=c!p2POfxF&|DIhVDd*luhhD!=Xj7CS7nX6iI#D*5P3}^mlBzR~V$;#8 zq)L@CKK5BAc>(li|3zLl?uwCxV@u>S3kwIm4RlH8HJX-e5!w^}2Btvp#q-EkS@Nd% z$eA$!pWbqQC><9QO5HFUD;HeYBJt|#)5OkQ3w{WKk|(pPl|Q?8fv-(z2v&D zXX9|*Z4NW!uDbVkJ_!po=EEtJz^W|Xk}thX%=Gtyt{7)Ix(z}+`H?>S&`Y>#$1p=(J0= zYV}Z^z*DO8sIOURk?5s*#uGeAA5@%@iZV;@9W?}}YbLqV^$C*)$HVe-$FQ$RYBm^R zCVu+JTVuX8*FjyREAr|V9v4P=bxD3J$gPzK@V&cs`!fBVXVTKb944o(C&i;|dWs<$ zFJ}IDq=Pxc_@i8b>B+QQkEf+8ZBydqvx)_STm7Uy$`KNMZi)ulsfYWj^rv9fkZY2e zr^@;p=fq9krmTmXxclkR9$OM5Qr*cvX^ZWYw~GcIu$`1mIWC=tk4X=ljhq43)6-dgk? zzN{rEM#Dp5O>Rhm26?`7Ycht~?6mlZf7DJWYb5}rGI1WW-Z!Fyw@H>Xgj+p(V9;w9 zGVWG3a#XWZQ&VjLhwN_eSKeLq3<->O2vx5tC=#xJGk$ zGCT+8;9V%46k|x7sX>yYqqQ?_Hn*O32l@Ps=Z<#}nPRi+Ydq<<;Ki;nQFG}vl|yUy z=yel8SDG9GzQJ{>*)XwRh9ag8kcQ779 z{&Go&mX$U`+!MSeO^4e~D4Cye`I+9?nh7ROK^Yz3r=F_NzyWj!CZBPHJk-b0lNJ{t zoVnI3w3f-qTm!}Ou`@@5LZu8mFVZm~FjTBgQq zhn;bEf~Sz!#7ehBT68xw`ge5R$|m<3rRNCCMpZ(~#;A_%;Zz57)^A(HNuC|vHuZxw$noa%O5&qaB6sS>Zm5D|P z&gyRIJQ(c`rcv2+MX{I^YHd|-ERwUD%6pY3bS}WrpDwE`vXuu=T#l#}>B z(<%p_iwU{7*eTUrLX-4?PB1Uc$D~yTHQR*=)|;)btTN*+9`aZ~^lY^VV^J4=N4L=nv<_sZ=7c`7TaqHT&lhP0 zOl199ZLO`*Mprw(&6@GvZnxK1G+`f>k3f+vqwsRMpA%TiXcapT!xgedCH46NML7-q!q4h3l3523`>JCBpEaw|&vpF{ksFw1P2a74e1fTdL)K zPFgSiT>S!`E;@clyKUe!taAb00Qj~=JShTs?}QIHJxi0diLPPk2uV0WEd0{F4!0e0 z^6K*xSU>QlAMy-oj*8}qR$@pOlG53t!&;@UHU9P@dO{FaurNrns4eW0a?DM@RsXHC z2V(UqIThWSTCTkm^{0J*=e?95DKB~2W-FA#icoP+{bkFuw-5shi#QAi^SW?aE;IhytJlwK;N`YeXWFH? z8;=ZiW!jlkm&P9nkidDgGm}h$9s%k#ovWOMYemmk*KQS$WWlIq^Lm~2b@Ybg621bA zn!dHdEwNSXwk}1+{t?&A_|Lq2JwCw>_ZQ4e#o4yFKEj4UU01n^(@d1zplF1szYAN! z-vBkIqhNzk5E!0j(`9e@kSm?ry3;j?@6ygISs`+l_EX>SQa|!i-}iFshS;u2yO`_h zepJybwyA{*k3U5YssCDV**nqs`xr)pbjisz9d~dZ0)XfsvngwRAXS`}xzNC2{(_TF zhPLvUj0AQYSlcoRMPtY7mZVJAWejBT#V9pB{v9V&+2xd8Yd4-PSi5h+<~>&a>t)|Z ztAl%vkR^xTdYkd*EFh>0NlEeRcOS~qWMaLvyi32-H3OQblPro#Gj#;kM%iyz!^#hU zX(*2j%WuBrQfg$lI&qf)xyP;%Z9|4vxuw~q#FSckH9yUA-89_V7LU4Cx*lz2CS{s6 z>(~vM;?)us4eYZhm#Qw@-H`aAq|=!yEA3rknnq@)xK1{xT(qc%rv;6G8sZ^Rlg9#uAbLB=>MX1?r#)Mc$uRk;y{!EcYZqwEx#6;gbi^#!Anx$P;EpO|C_%RG+(p#H049~tI)o5YJ)nX z_f#%g8uQ_!X7K&2R$?)Y+@9x}uClbxvh1HsBw;< z!|{qqu+o!L-X4t`h?JATbpXQk@P>|)Z~QQa(h>U0%rv^(jW@RvD zmsAdiP{pKCa|OsG8xH48_<#>$mnhIbhTcj$1siEM>G<dWLj|5GHKt5*sp_hW&ykA7XCl^@$wjwwk`9{+oD{+eApo$lIUl-Yn)GYGI>5 z`WJD15{Sez;>?jG+WElmi2Wm@j_j3}-x|FqaxZ^0?EX4RlPS8gd8+#YyRxlRQBS^* zo0zlG`X1=rj;Qs*cU;(5@OxRnb(_n%36Vs=RMjZ8cVLPp&$JCYJoR%V&A20(jAt)_ zJC45a_l_}#TERZiOIrI{!990?+1Wwn%AiB-@I(W=;@j59phNayxQEA@DK1QtTWMIg zA&R9zg8euatc@Gm7#yydJq<@~Jtd3o^~PRoC)Stm^|R~rUs@K7qlulAh-hv>MGrPl zdnOV~qe_@>Q?~n7TW8~%W3w&x5`Ai|Tg|r5Y^wYeWsC3>o|&c)tQ{O39@09>YSZ}l}()?`17^3$DMhN7MD`&n9pCGns`AO>PAwC)LOkh zu2-asMgQolZ{=JubgupKlL0h1l{k~^fc$i1QOBi1>fl;!+8e+F;Nm+ znsu3;WG#?5 zm`6Lhv7Z|Ju3yH8Rw9sKgra3(x>5HYaco}p5D33}7tE0VdunV@pdU1fx}bCS$Z~bI z_M$F52F~_WU6A!_h1jcy_ZWU36xxdjNSdo4*wJ?0r%sW(^8QiB4;XY&dJK@Ab$_&= zeZAO%d?m)GebxK!+k3Jk+(iLrb?c>53Z*+u@+t0;8}?H?&~T|AoN&%CNM1P-1{*YwZ^mR&fq$vvs$G_7%4Tn z7yS%6kW)=PUz%z;kfY#!xWuKo_nrHJXJr1*N>abgX%+-mFe)hiS$9+~NQlb$t^g_I zD;O7F(!4Vespd5jC%`S{in~F8dE;KDSn;qVe{L^OCE-YL%a#>y%+A)gCNDM0d2aQ3 zqlKGmU~Q)eZqm2yb~TPqR%T6@T{f2e8x~TWEqRvQIqS~Z_1=u9QqEpQb-91*RA?*s z$Ji~^vALCswehTuH4(fF z8~+&QK9*JmS#Yi86&1PvC~nIlo)xDCy4Ix+kom^CC+Ca1v4H_@eMs=>lKl3%cW2C& zyk$R8uD$qf;_XOI?i5#AJ>$+q7diyE{Yv1HEG?cDr#W+{1N14li7&NUiK9_Q=aFDj z*WwOwXYRKUbquU?Qo$YgxxN@=TYhVQb=U*nibxuTI6nfya3_!H?F>9upY57!L39v= z_x`rf)3aCgwY-Jbhw4HTRfwKM0(H}7Tabh+_gvoWkFS^^?nXKF-ns1S<4+gc@@IQR z68t=08AvYzQ-)0&-YOe=9yhI??{1X$KgBlhp#%(UR8$_TzW!Rz6=27-CVe#{5t1N1 zlyf2lw-3w}?un2j4Xl6s?MG(jAA4?^Ja9i0A&8BGq^N`OjQQ&TXvT@Ms#-l6Zr~__ zMGjAYOO%v+SK~;V9UWFUvc!3Xy2Cj0_xC+H z6&Dra??;)H#_$_|FH;jd9b$bUJ<7v)p#}H8LIJ#;@4*G%15y0H<|0XQO{->}Mb+s|ER{+12 z`Zrw(_{72vmRMjF^DkY=23BT&IoCgRC0L^I@czYL|5;aZvw@%e>+k+MT?r<0ET8^C zNkfx+a4wfFv{jWmQtrQMg+e zfeP?E@>!C+PZydg@com zLFdtv6Y?MY72)`Yu~xIlLzrVZ`7t)Z#^1j(YF0n5j5V=7WOdlDXT;%>*a*9P5YZ1l z-u}X>zfFFHnLox}iW8NcILJ7+i90A+u4fVio3R z_x|MdfSSz7BpG2ga1;QNNY+}s5VEvNYckNF8oC91|qV&A# zYr%2{EvMt&DP`k>03KC*&gZCKbn-a(P2Q|qbe)`{jdaB#N$DigyK4N5Xu)tu$Y;N# z$DxaKE$)>Ep~o*bk9d&38z+$b%yIhk{b9Nehh%w=kdpvAN?XqtxlPn$Qp)t zYoQF=f;JO^H{=6iS5%Sjpc?dzhc!l|XxD^M$%5gyiQ}C^s+)t6D}v-R(GVH?3V|1U zUqL#AE0!!tqxvq!_0~#%+f8 zTtn)|x+jEV1dlW>4StIahd(XPvze?+M%qrJ+%`X2caP}Y{cD9K8{A^nM~`axm&8wIS>lcp!z#k#bL56bW#P@FFW*&g1#mj|$%iJ45jX?6pHU8sWP7@ix%) zVi-eC%CPSm#QKcjwM0Hp8{;hyCc3G_`NTC{$};t0unfM0xXoGbwQRso-o#;_(xKjH zk_>rMRq#ii`se(@0&4EXqv=QUN(Dulj8m2NA|1j^*@;&(-qw6@dScjlszGNN%;xde zepMi4pm=4R5;19kD*w~6u;>r{{u zh-LrYT9;DQ;3GhAQKqO(8wj5Us87jG{*um$e;;m3DFv@X%M?64@w-vcc2s%zN5kYC z=4_PA0a{jw#p<0JocMCoF9S44B-vD|B#^xck}wxba8DSa>!k6GBI8lh#5H@IeuNr)nWJIg^Rg(Y7{q=GgAC~=e!WsV%k+}ESfyXg2lyvi}=V1LN0=j3ygS>gEn zllj-^W8KfB);MN4{!9eI)0Tug?J@oKra-&jln+YF@9l;=JZ?Xxq%C6!3EQ~@7RVI! zIm{B2gA67;h*x8XJ!;J;3HzEX%*Le9xd3l*_GfEk1CjfL6oePtt;S;W{1n7uld>zW z*gq=Gm33neE?sR?5XOMJ-d_(ZpoOvDc+N?XJdwDNG?8$SERkrC2wN8=!X|tOvO-b#FX!a0Kj^LmPBj_i8MeL9sH3eYG}&yVbfk+_5+URCa@3 zsF*>;mC#0Lt$TO!h$K+Vc+Jv?b@PS11armEvhKlH)40VxXw&m=*;;qjEDEca*%};n z+2z)$G}eX7?lo1B*`1og!tG&A$O$f5$V*fCJ+OFk0Z)%N?>Akx?2`>Kr!%o5+^5_t zKxqnyXZ{{QR})Qem9qcclur}r=4})Z$CCHy>+;f=r?obpMF_gzLn5N5y1K*{m;(Sm zPEsqU<`o_aaZ+kR%J%+sXRI)zmf`aIbAczQ|F#y1&^L)Z?nX2RWXB9no{)PX`96`# z7tu{7il~jQJDB+b^W@Hd;E6(9NVzl^^Q;(7JFn?Qeg(q~4*LY4MQld%<-HHVEh6=Y zYa!=<@M?W?MLQ8A84~y|ot1QB*E#`9#uN+@{t=E0Neu9SjYaW>A*LJ+5`iOU3Ju9p zLmH`Kos*-J>cNslLlFZ(BSnhB4Fh-{cwbOV!o^MKhD?Yu2OF1mzpse%KuD1h!Be6q zih;E7kV{m9L>b*U56lXQOrYaMd2sfv&b-vgh>~ttok`-Qc|Oj_{l=d;y@B8%m7^Vk zj+Q11b;gjF4Tudy7^DZ_n@~roWTjq&Q~|I}u%nihBb*7M7K;eHMhUX=U!VlD&!bnx zkcarf3ko}2O)kt@<1NXAFfA$UgCmy;=3=RN2rbEb;P%I?`HjLs`dMjwi92Y6Qdx1% zBvE%o=udml08$goDBNL)@M)rU5w#1-R`(oqme9ZLjf_OJH|v?FeGQ5wSR(CS0%)UFSO{E3GMjge2bqHh9P zTN{*mVYvs9;haux_#1Kdnc;RLu7{@K`e8fB^kH{L-X0oR9#H%XhFP?eZZtuG7hav+ zm_5Yb&>VyH&>h1!Rh@=u)`CI(kML}xe4TH1Bb{Bvx)F%r6 z4_D$KvNxo=4wp`15)lxZK=h5tTBa{{APQ=kVTci#KlUF;5-E^ec*6kY4Pv+pha zh-NQkY4V0Hir+-~qT_}U#Y+@o-_aY(gnMYW@KYy;2OLS5L9{T+He5llAY4KCm?~@0 z_B~Ig5VR867OWD*+owx~UN|K;5RyQINB;2*FX+?BWt5dF>%hlw*5cj=rh{2G5X7aD zAZk|B4K)ht;2m7h@V?Xj$dafxeqh)QHi}WiE`>kx{zo1p){4jBA8@E2bUWa7!&d>P z%;B?xo6dOq*JxK!UV93_-G~m=*&)9huA!%WudF-2@Yx}BZ`uc>w~ss0ppQ{O;k%Rq z6Z=ulR1ci~P(c#j@xzDCSo;NNe+YykQPBe-NXs4v;dvsxQHi8M^g|VUvo~x*vwKjP zf1rKQ{$L9!{EX-yEI{KVJt|yT_pA(zX_Lh>86A0E(o2|!0ZN0G#X|a=P zJfZ$=D;1xe(w8ldDjy6l9tBlgB=V+gK{q#jG96DI=x0&MhIYO0%{*3Sn%`(bfd^!T zPzmz0Ae+&Jmw8WEu8EL#?Ehr0ymp|z3Wup)b08kgY$65-0`Z~39- z?3e8InPOS=F&YZ+<1|lT!V&~f%bj&yEM)bMTOs7CW}WSf$C3jKIy`obZG0*& zNINs5lQp9fd(RrIOkhfy(U{yR3IO*?=R zfGukM3yNvZ<(qe^<^QPetb^j(wsoIiL4v!xOK=O2;KAJ?1h>W-3r--oJBdZKVr^1)!1^=H^E)|16pnCLP_ z>?6CY1~OajPbMaZm(`n@AGH;&;FC4Stuh|MPk1^~U~pdOYD^swYA78`o09*^ zKc-Kvb^FYSk6k-NS1|YBJoCr6lt5iGixB^GfAGthdf_}_S(mjKk61xqNx}Bs_e?T$ z>FLxikyQs53dxxfF$Ru<~5@A&% z{x}GAgpehjmlZb;X_9*q9ZhoM!tF}t(e$Ziq|Nd9x)X|+8f244f02{K+lNW5Lu{Zw z`dG{-3~00xp5I$EaE~P|Qxk|4NH9n!T>PjXuMb2=YH5&!8;n|;HxLobFmQ+7ea8vY zK8@c!gFKZL(ELt%PUxpLq4$(cyR(4x9#ui}C&fc)3cIWFzPxEC?OI3;YE&MpU(hV- z#fm-bXmsa(Mp^E=GK@_E#eYnOWn6D>9UVZ_Kuyag@~yB8^nmZLc%h>usZ)a-!>BHc zQBqyBxA0R3#>6STl2Ys}8q!v5Zx|*aI?sSaCK~bxD{DF)C-pA<9BQqcqd+b0scPB{ zRH@IAHT|i#m!;x=&MD_$GcIH&%obZ!&On}@jZUff{Gd4CJ;BGoVLO;Hkdp|{LD-)Q zAeDxz(cHm3;F;X{62IgKM&z#}&g>uE6yG*w3k9P1*P%6~6+1Jbl$V1hy!P+oOUgDW z;v3*kt?Q@dS7JE$40a7QQR)h^BHv|N%au@dY~1PX;fu8K0t5>ihA^opDfNf?1^Cjk z2upgq_Kbw@IhMxZGtb_r$tiX|l3xkt;Ip_T;`qYS979NmL=AvSQVM=bucNt-tMdRdT7e_uM_C?fxlD5CaH}Vjn7Rc0})CH^V zu)If*Fv43HE>QG-ryy5;vvG5qIAPYTpWvo5cLOpY7t(_w;p^(@i4`}HiW#cS(qZUX z)2Q1_BBVwbMgRJS>g3zFINNkp-o5VEa5KC-@Ru*)sRBY~{N{}dr0zt>Ih_r3=T(HG zPvr1+vFW4a#&tb4OL3{X;-l%>G;2(ZIh}|ZHA3-13S`=uSoh6fT zghHKBGkeSF#uU2OOMM99m_vq0O z`FOKvu83Z)j*eO$dw>i9t3;${cj~Fu>^Z#L$P_|hzRtT+IxESJhe@8!?hKk?oHr=R z8BD0$u5{x^-qkispN=nJb>OBlG$Zt|Sr*R||6pHsJn1&azWhbT7a`Goy@T}9Vz?DL zr6&vePjxNIw)Ky2D8@WJ8rX((K%Z2tKC)?vJAF|v^emBBF59QL;RuG2@$mUWCnT~k zc_xDuW7%d86j6>;{i$4M0TCc}oox$7Wy__qjaRSABsY6h>050M-c_PU= z+=0v*a+?!5GDL}5+K4=!lPM7|cv zHD~*LN)QM6Wo-?;R5bmuA-u^wjVVEKT0mEgcsrZt`F`L6h|t8t?m-y`G(`M^TE;DD6PDbgYIV#JmV zN|kLiubgJRR^_y0CF;X_KuN0&bDSeKS5cM=fbPc|;b~ZXD)U+c-D;=K1;3L1B;yRWdGa zGOo=rb)Kt!)skfT_DFqYrk?WAY|B3Ln^W*Y+;;I6yN~U_r(>2KmYokFryr7a_$|ut z$Gu#&nJytFwJ#>3Uqx{9B@-IQ2GfaLcIg_)8cFQ5ot_y#M zCFvd&+cS7hc#;8)*qbzh7DP$Z$Po0#a72(A;M`hDZh~?7YH2hrWZ-PG&u?*ELxFTe zbkFQ%UKbr&YJ|)3VFoKi4KUc3cg%e2i3~rN-i1n(b87&b`(hn>WQy{Q%#IO5J=m0w zYnDpsNgPTbw0%UMtN@t!y@Fs`Hjbhg&0?0il-@y|C_0z{D>;IE9dBWXV@u)MdXUjDf1)&ZT)$2BS`=*#3LZ})5?g=+fi0^p-i$(IdWYyN zLd)3qiAH1JCYe3sQWN96O5;2au8ua%pZe`V#aPh7C*m#~tMEcJ%6#5GTHP}v zl9_?MVI1famQ6sh5b+K18J{8!`NYD-vAu-MOtNmXMT+yQiEPX(%TX8XvPSDFoH1Rr zq$K*?%f|62)lwULP)O{Xu}zBsxO|QQyVYk^FML^<>+KJ_HMJiIm(iP31HQ>dNsb)D zWU7pT3NOTQ``|dooSoM&%mhCi%+D0XGJcMiI-c+57%`MRgil-1F=xmdMweew)Qk@9 z+oYG5GG0-bnU z;+Qu(E0bVa0~jjnz$uPELXeu=yW>54{QN<0@9VblmiHR#m& z2`7iJ!6@~iC3eodo=MZ$!}aoGsgfq*1~7e7-u~Cc_^Q!)x@)Rina>2Xlmo_iS0A}VMdzYH|OVCAoZB8%? zfSmxtjfPotdU$${bXG}ML79bmR5Z^mNdGksr!D6$N5atb$@Jc|Qss={mPV*@PqVdB z=cBUHdHl0_UtM2@__|=7nkH~;rTK#TOlilh!jgMbU)x7&DGiCq_xD9A%>!?qJI;)J z564ZA5IR@VI{aBp=?nmu9v34Q78PXx`ZVbM?RgXU2_jLy72Ua5U8a&v(WPGwaq1YA7uX*EC50h@^3_hm+v-A*t4oQ^TwjyDhq z{1J@N7gynPSoK6g>ZWGx^%c#b2RgY`{|HsWt91os28B1ZG^kGpnN(#STU*U`yU4Nh zDRS0l7ex@x6cr_Zt{5lLeidVvY05rjp2?u5(^D1<6hPJEQwSbr>&tj=-dOhuseMni z*K2#z&C;}Jc0(4B*IO`|_ccu0Pcu@R7MeO=q?3d&j$++)koHVM+mJnN0?)!qMSP^;v9OWiTr7D zhEo7dk#*#qSh!en|bvCTV#SK zI~`(&`Br~PqTOPF=j|eb0|po!RjRCTp0>m3+v9IpaTZu;R$>rZz3YlQw|mD2od=Hx z&VVUXZHFq8+}_$o*CZ>(T7yO**N-4spHYRgY=IzcYoe9Vw@!>@a~$jfARRm~IXhoM zrSaJ5SEX&=^dXOiq4uPvy=Q07HrG$+@S}r@=dAVJZ%1FtM};vqk}=@i&3R*5LznYJ z?&37R=~E~Txu(Nwi7vQ~o}_IwcB5m#mJjglQ6rxgeWs||L)^y1>3NK~(BPyJv3B>m z+@u1{JXKH+zu#y1%f!Z-;B;FIslS*-9OX_(aY4kwft<8bT^JdXLkRlRT)blK?;4{n z;1$StQD*9dAbTfPghbJOf)x?yi`O--?ZCzSu5n3iNTj9IWU%LvfnF zSS)6*UTE~aA9+aVE=sGEW}=cvGxqg0IJ3O;9m%O&Xp85q$I?4}b3;E$n+u|EYa(L0 z-Y@5HHhj+pA)+V*37Zda2YVW|S<#&mt?+WzYmHl;it^{aPsj?-P%8JBDi2m;!JS4k zMdL-)&SIfEwd#>lCSstYPe}b<#Dv6$7M-WTj-Wt^E6+fRmf(km&_IhSV@eX#a=f~D z(lp`L3r6vE>SLl|Sf@c~!X&Gk<;;xwa4chiD3@HaM`7gD7wup;9GgW)s3OJ8Ls9GA zVTY6Rp-o)RETowK2zoDh(J}kBR&^XHn-$1TX?D016(J$EuH|)hs*q zxR_(e+nOxcx?n`w2sSu@E9M!&ZjNpTo|G<>ZUd|1d+h1C60XRlZ4fmN6ZD#~-t-)Z zEQh;m_t@4m-t??OYu8WwuQRzK3mPOFZUDit3?H5uWrYaXt}^eicd4ikWZ1qVI6iqL zsF6-qI}|X;d)7CEiKRqTi8*}WaxKnvbQEf5l0D#~OuFng@&3F^vZUO(U25!d4Iv0v z&nfTIE6+9DUie+Uh06EM0aU;%@L2T}Q7{6n?gP;Z?DfO$mt4Q~rrs+q>)sXaHx|W7 zPGE(L2xj%Fg9IpwOlyvHI4`)8*<2Ywj9i_&4XwZ@bPm~N5L{q|%)KcW z%veY;c~*dx?(<=vU>UGr*mE7+?Ln}KQDx=K;rM3c-4MYmf=k zw)s}OP^V|3q>fjGiXp|mZy8K7dSV)qu%C`y6xC0s9jCVYy!(%)P;Lzy_>lw_F7 zG~K2|1WMn2=i8Gf)&@M|3R2H;bT^TU1|EE0pHEG18NTBAEOA@)<6v%SZrtam$-}{e zQ@gf3r2}CQz*n--y{Ccx{dCkYy5uAx;YX1+gg{+n;@zmQ;0QG6YB1-#pyL-Nry4-r zkIxb6qDt(UR%Q%Ds@N~)_&4cuy5sq;WUuon@yWwtcilwf`7JT)j8ee$9(dEfSL7wM z;l8dwtYn8K>U+gg&MZvo`Z6`RcJ6R)q~^nYDQl)rjAEG1dKI_lOKt3YDR(ZmsGP;_ z(&I9B#maJYp;wKGQciL_O8c(!0!H&xtp~-_Vz{%fJmjW=Yd=a;>>& zAM9trdrGJS_8cSWbP@r`Yde{9P`%Q0Q*oNuS6m_$L-j@yH1xL(6tSL&3U=z8F@nb* zoO4kx4u#^fy3K^JDD|{;-<&P?UJS&7mFMrF<08@2sw1^Y@xIQF_v2zPJvnZeb_EvE%0;HRs2~&K&zZ zJuNSpiQ9qzr+#F%?{tmwc~iBtZjvLq3s zBF%nm`dZ<&?1%n4Kl}^%Qrw?7-{ty<(>kcvbftS#nL=jPPNFcIrcs>V8Sp)aHkIpn zkd8ZC2f=*dugCl*e#31IQEKF`OLa#Si{f2e0zy-_&g?z;ME!Wud`2>s; z&J+x0eEI;PFa6r#Beb7%oKWCZUZKm~etW<$x6eQcU|gn%klNYU0O^NsO$#O0*Tz7G zN|;3aF2k;BrLMq@G9weNvcH@4x|=l}dzK;h#|vb0zhPyNfe?DBDbsQ*>j9(rJfpyD z&UrUcZ&k5L3!g!NVD~_|!kO?}K?g+Dl8gyYXc1`O> zDcUG+^{cjJB@@%u!?OWhXXCGipeGNXDo-?8O4z+}?REnn*p+x4)>$o*%@ zvO{lwzQ2nyC7^|L@7le`d{MZ!KwRiwWn$Q);8h5tqwd~f2q#YcHT>5V&Z{Y&k5>Ez74Z1EF(xs*?0g z_~O{dHI^itYV50T`jS6CD7ansp?}}dpp(dPMXUL=)lxlx^D~Dx|IOac0C9McN)bb@8Vnykx{0my#J|hEf34Cl(kXDrg#5DEU zrj64Ht_U7T9x#0MuDWV|@U#9G123a^1IAB^+TDh4#j;X2d13dGks+xl8KapKAo>V< z&$wOO3KJf^7KeuYJS9&N)!c?7>nFQl6NXc&5^~07+SL>MbvqX%4y=YF&mSW0(H|V> zZhN>>Cj5$|C7ja7aQ)`D9&@1UB_tY4G+Sn5hy?7EkoL_zpLa|y2AGfpUOzu8LAtsx z<>Rrwi5e^(zL=?gyEYb1_k7`~^}Gv>c*vH*1ClebaYjc!KlqH~>PQbz@Dqq+jl;Y} zV%dq|+Yz1ykzp4Jb80tYx!`eEz2GF9P<~2~Y`d=v7YAn`Rc7H4;oK`7}<>n7=~!a?@yBV^dHZxqDTxX$_+yXu2ez(0~g; z6~l0>DIS$c@ZO48_R!sS{?QYB=9mVs_r%O$u5|$OiDvP4o97el(br;0y-UDS@k7`= zV<}f|MGs>zd!1Etgv5&gdP3ZF)dD!z^qR6wX``y32YZDf;JQ!ei5KgVdB~FGXCr<_ zN3HXf;bB;E;qojiZmFV z*Ws7d1rybQORZDm?7ZBTm}ebrE7C);Dd`+`zekV_Z1S|yuiVCs=!(wzfY$It04d|6njh2#w-aPpxbk~7uirAAJZzigA#)Y0J0 zGGLC#!CR`q$lOdvY8+!&Dn$z}n1-G<{ZU;DUs8FDhBf@|jH%EE zCR|^G+hr!wqaP6qES%V&Vr+<0K2)P30k!V+VjDcX(!JZ-pjtav#55f%3l#mj5r}>0bnqKfXB4f3D1*oCALcrTUlR z`hVIz07viqMqBy=CInaT!(mH*M^5^OJ>Xx2BojD{2cGyh{G(rq0)N9h`bYeqfTRBo zhS4uJ(f?r=asRh5i+)Y>zh)G1|G_3Q`8#{Vzro7>D;YZ!ii+noBM zuNa?loIzdk#A7rQ-)qn|EwT9BOxodzxV3N*70Y4ru_`GRdd--C4fYNhwyCIIo!cXk zl*u*Uf{nf%sO&puyfh$7E-yep@fvq4F>OY(B>>#YHMZ67FMB@_P*J0WGC~x8==AP%niA&(oxQqyz8ZUJOM| z4hgela`z;1eqI8rs?eLP6PK>!M79K6!#0r_shNZYiqf= Xn*rVbb7Kj@;ex{GjEu5sa_Ij7_B$}_ literal 0 HcmV?d00001 From 86137fc78ac16ab4e38feaf98b1fb803c4add43e Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 21 Oct 2024 19:04:51 -0500 Subject: [PATCH 56/93] Create Main-Windows-Script.py Added initial code --- Scripts/Windows/Main-Windows-Script.py | 0 1 file changed, 0 insertions(+), 0 deletions(-) create mode 100644 Scripts/Windows/Main-Windows-Script.py diff --git a/Scripts/Windows/Main-Windows-Script.py b/Scripts/Windows/Main-Windows-Script.py new file mode 100644 index 0000000..e69de29 From 5be5f58dba601a9696469cd90ab4a566a07b0a4b Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 21 Oct 2024 19:30:21 -0500 Subject: [PATCH 57/93] Update Main-Windows-Script.py --- Scripts/Windows/Main-Windows-Script.py | 191 +++++++++++++++++++++++++ 1 file changed, 191 insertions(+) diff --git a/Scripts/Windows/Main-Windows-Script.py b/Scripts/Windows/Main-Windows-Script.py index e69de29..b2a1692 100644 --- a/Scripts/Windows/Main-Windows-Script.py +++ b/Scripts/Windows/Main-Windows-Script.py @@ -0,0 +1,191 @@ +""" +This is the main script for Windows. +All task for this script will be pulled from the windows cyberPatriot checklist. +order of the task is not yet determined.(possibly no order) +""" + + +import subprocess +import os +import fnmatch + +#enable firewall +subprocess.run(["powershell", "Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True"]) +print("Firewall enabled.") + +print("audit policies") +# List of audit policies to configure +audit_policies = [ + "Audit account logon events", + "Audit account management", + "Audit directory service access", + "Audit logon events", + "Audit object access", + "Audit policy change", + "Audit privilege use", + "Audit process tracking", + "Audit system events" +] + +# Command template to set audit policy +command_template = 'auditpol /set /subcategory:"{}" /success:enable /failure:enable' + +# Loop through each policy and set it to log both successes and failures +for policy in audit_policies: + command = command_template.format(policy) + subprocess.run(command, shell=True, check=True) + print(command) + +print("Audit policies updated to log both successes and failures.") + +print("password policies") +#change password policies +password_policies = [ + "net accounts /minpwlen:8", # Minimum password length + "net accounts /maxpwage:30", # Maximum password age (days) + "net accounts /minpwage:1", # Minimum password age (days) + "net accounts /uniquepw:5", # Number of unique passwords before reuse + "net accounts /lockoutthreshold:5", # Account lockout threshold + "net accounts /lockoutduration:30", # Account lockout duration (minutes) + "net accounts /lockoutwindow:30" # Reset account lockout counter after (minutes) +] + +for policy in password_policies: + subprocess.run(policy, shell=True, check=True) + print(policy) +print("Password policies updated.") +#change UAC (user account control) settings +print("UAC settings") +subprocess.run('powershell.exe -Command "Set-ItemProperty -Path HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System -Name ConsentPromptBehaviorAdmin -Value 2"', shell = True, check = True) +print("UAC settings updated.") + +#disable admin and guest account +print("Disabling guest and admin account") +commands = [ + 'net user admin /active:no', + 'net user guest /active:no' +] + +for command in commands: + subprocess.run(command, shell=True, check=True) + +print("Admin and Guest accounts have been disabled.") + + +#remove malicous software +# List of software to uninstall +software_list = ["Wireshark", "Netcap", "CCleaner"] + +# PowerShell script to uninstall software +powershell_script = """ +$softwareList = @{} +$installedSoftware = Get-WmiObject -Class Win32_Product + +foreach ($software in $softwareList) {{ + $app = $installedSoftware | Where-Object {{ $_.Name -like "*$software*" }} + if ($app) {{ + try {{ + $app.Uninstall() + Write-Output "Uninstalled: $($app.Name)" + }} catch {{ + Write-Output "Error uninstalling $($app.Name): $_" + }} + }} else {{ + Write-Output "$software is not installed." + }} +}} +""".format(", ".join([f'"{software}"' for software in software_list])) + +# Run the PowerShell script +subprocess.run(["powershell", "-Command", powershell_script], check=True) + +# PowerShell command to update Google Chrome +powershell_command = """ +$chromePath = "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe" +if (Test-Path $chromePath) { + $updateCommand = "$chromePath --check-for-update-interval=1" + Start-Process -FilePath "cmd.exe" -ArgumentList "/c", $updateCommand -Verb RunAs + Write-Output "Google Chrome update initiated." +} else { + Write-Output "Google Chrome is not installed." +} +""" + +# Run the PowerShell command +subprocess.run(["powershell", "-Command", powershell_command], check=True) + +# PowerShell command to update Firefox +powershell_command_firefox = """ +$firefoxPath = "C:\\Program Files\\Mozilla Firefox\\firefox.exe" +if (Test-Path $firefoxPath) { + $updateCommand = "$firefoxPath -silent -update" + Start-Process -FilePath "cmd.exe" -ArgumentList "/c", $updateCommand -Verb RunAs + Write-Output "Mozilla Firefox update initiated." +} else { + Write-Output "Mozilla Firefox is not installed." +} +""" + +# Run the PowerShell command for Firefox +subprocess.run(["powershell", "-Command", powershell_command_firefox], check=True) + +# List of services to stop and disable +services = [ + "TermService", # RDP + "SharedAccess", # ICS + "UmRdpService", # RDP UserMode + "ftpsvc", # Windows FTP service + "RemoteRegistry", # Remote Registry + "SessionEnv", # RD Configuration + "SSDPSRV", # SSDP Discovery + "upnphost", # UPnP Device Host + "TermService", # Remote Desktop + "W3SVC", # WWW Publishing Service + "TermService", # remote desktop + "sshd" # ssh +] + +for service in services: + print(f"Stopping {service} service") + subprocess.run(f'sc stop {service}', shell=True, check=True) + print(f"Disabling {service} service") + subprocess.run(f'sc config {service} start= disabled', shell=True, check=True) + +# Disable remote desktop +print("Disabling Remote Desktop") +subprocess.run('reg add "HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 1 /f', shell=True, check=True) +print("Remote Desktop has been disabled.") + +# List of PowerShell commands to block the specified ports +commands = [ + 'New-NetFirewallRule -DisplayName "Block RDP" -Direction Inbound -LocalPort 3389 -Protocol TCP -Action Block', + 'New-NetFirewallRule -DisplayName "Block SSH" -Direction Inbound -LocalPort 22 -Protocol TCP -Action Block', + 'New-NetFirewallRule -DisplayName "Block TelNet" -Direction Inbound -LocalPort 23 -Protocol TCP -Action Block', + 'New-NetFirewallRule -DisplayName "Block SNMP 161" -Direction Inbound -LocalPort 161 -Protocol UDP -Action Block', + 'New-NetFirewallRule -DisplayName "Block SNMP 162" -Direction Inbound -LocalPort 162 -Protocol UDP -Action Block', + 'New-NetFirewallRule -DisplayName "Block LDAP" -Direction Inbound -LocalPort 389 -Protocol TCP -Action Block', + 'New-NetFirewallRule -DisplayName "Block FTP Command" -Direction Inbound -LocalPort 21 -Protocol TCP -Action Block', + 'New-NetFirewallRule -DisplayName "Block FTP Data" -Direction Inbound -LocalPort 20 -Protocol TCP -Action Block' +] + +# Execute each command using subprocess.run +for command in commands: + subprocess.run(["powershell", "-Command", command], check=True) + + +try: + # Command to run a quick scan using Windows Defender + command = ["powershell", "Start-MpScan", "-ScanType", "QuickScan"] + + # Execute the command + result = subprocess.run(command, capture_output=True, text=True) + + # Check if the command was successful + if result.returncode == 0: + print("Quick scan completed successfully.") + print(result.stdout) + else: + print("Quick scan failed.") + print(result.stderr) +except Exception as e: + print(f"An error occurred: {e}") \ No newline at end of file From b77ff9088a92aa25b3c849a05b03eef4e1f346ac Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 21 Oct 2024 19:39:41 -0500 Subject: [PATCH 58/93] Added more --- Scripts/Windows/Main-Windows-Script.py | 201 ++++++++++++++++++++++++- 1 file changed, 200 insertions(+), 1 deletion(-) diff --git a/Scripts/Windows/Main-Windows-Script.py b/Scripts/Windows/Main-Windows-Script.py index b2a1692..6886c97 100644 --- a/Scripts/Windows/Main-Windows-Script.py +++ b/Scripts/Windows/Main-Windows-Script.py @@ -188,4 +188,203 @@ print("Quick scan failed.") print(result.stderr) except Exception as e: - print(f"An error occurred: {e}") \ No newline at end of file + print(f"An error occurred: {e}") + +# List of commands to stop and disable services might be overlap was coppied and pasted from previous code +stop_disable_commands = [ + 'sc stop tlntsvr', + 'sc config tlntsvr start= disabled', + 'sc stop msftpsvc', + 'sc config msftpsvc start= disabled', + 'sc stop snmptrap', + 'sc config snmptrap start= disabled', + 'sc stop ssdpsrv', + 'sc config ssdpsrv start= disabled', + 'sc stop termservice', + 'sc config termservice start= disabled', + 'sc stop sessionenv', + 'sc config sessionenv start= disabled', + 'sc stop remoteregistry', + 'sc config remoteregistry start= disabled', + 'sc stop Messenger', + 'sc config Messenger start= disabled', + 'sc stop upnphos', + 'sc config upnphos start= disabled', + 'sc stop WAS', + 'sc config WAS start= disabled', + 'sc stop RemoteAccess', + 'sc config RemoteAccess start= disabled', + 'sc stop mnmsrvc', + 'sc config mnmsrvc start= disabled', + 'sc stop NetTcpPortSharing', + 'sc config NetTcpPortSharing start= disabled', + 'sc stop RasMan', + 'sc config RasMan start= disabled', + 'sc stop TabletInputService', + 'sc config TabletInputService start= disabled', + 'sc stop RpcSs', + 'sc config RpcSs start= disabled', + 'sc stop SENS', + 'sc config SENS start= disabled', + 'sc stop EventSystem', + 'sc config EventSystem start= disabled', + 'sc stop XblAuthManager', + 'sc config XblAuthManager start= disabled', + 'sc stop XblGameSave', + 'sc config XblGameSave start= disabled', + 'sc stop XboxGipSvc', + 'sc config XboxGipSvc start= disabled', + 'sc stop xboxgip', + 'sc config xboxgip start= disabled', + 'sc stop xbgm', + 'sc config xbgm start= disabled', + 'sc stop SysMain', + 'sc config SysMain start= disabled', + 'sc stop seclogon', + 'sc config seclogon start= disabled', + 'sc stop TapiSrv', + 'sc config TapiSrv start= disabled', + 'sc stop p2pimsvc', + 'sc config p2pimsvc start= disabled', + 'sc stop simptcp', + 'sc config simptcp start= disabled', + 'sc stop fax', + 'sc config fax start= disabled', + 'sc stop Msftpsvc', + 'sc config Msftpsvc start= disabled', + 'sc stop iprip', + 'sc config iprip start= disabled', + 'sc stop ftpsvc', + 'sc config ftpsvc start= disabled', + 'sc stop RasAuto', + 'sc config RasAuto start= disabled', + 'sc stop W3svc', + 'sc config W3svc start= disabled', + 'sc stop Smtpsvc', + 'sc config Smtpsvc start= disabled', + 'sc stop Dfs', + 'sc config Dfs start= disabled', + 'sc stop TrkWks', + 'sc config TrkWks start= disabled', + 'sc stop MSDTC', + 'sc config MSDTC start= disabled', + 'sc stop ERSvc', + 'sc config ERSvc start= disabled', + 'sc stop NtFrs', + 'sc config NtFrs start= disabled', + 'sc stop Iisadmin', + 'sc config Iisadmin start= disabled', + 'sc stop IsmServ', + 'sc config IsmServ start= disabled', + 'sc stop WmdmPmSN', + 'sc config WmdmPmSN start= disabled', + 'sc stop helpsvc', + 'sc config helpsvc start= disabled', + 'sc stop Spooler', + 'sc config Spooler start= disabled', + 'sc stop RDSessMgr', + 'sc config RDSessMgr start= disabled', + 'sc stop RSoPProv', + 'sc config RSoPProv start= disabled', + 'sc stop SCardSvr', + 'sc config SCardSvr start= disabled', + 'sc stop lanmanserver', + 'sc config lanmanserver start= disabled', + 'sc stop Sacsvr', + 'sc config Sacsvr start= disabled', + 'sc stop TermService', + 'sc config TermService start= disabled', + 'sc stop uploadmgr', + 'sc config uploadmgr start= disabled', + 'sc stop VDS', + 'sc config VDS start= disabled', + 'sc stop VSS', + 'sc config VSS start= disabled', + 'sc stop WINS', + 'sc config WINS start= disabled', + 'sc stop CscService', + 'sc config CscService start= disabled', + 'sc stop hidserv', + 'sc config hidserv start= disabled', + 'sc stop IPBusEnum', + 'sc config IPBusEnum start= disabled', + 'sc stop PolicyAgent', + 'sc config PolicyAgent start= disabled', + 'sc stop SharedAccess', + 'sc config SharedAccess start= disabled', + 'sc stop SSDPSRV', + 'sc config SSDPSRV start= disabled', + 'sc stop Themes', + 'sc config Themes start= disabled', + 'sc stop upnphost', + 'sc config upnphost start= disabled', + 'sc stop nfssvc', + 'sc config nfssvc start= disabled', + 'sc stop nfsclnt', + 'sc config nfsclnt start= disabled', + 'sc stop MSSQLServerADHelper', + 'sc config MSSQLServerADHelper start= disabled', + 'sc stop SharedAccess', + 'sc config SharedAccess start= disabled', + 'sc stop UmRdpService', + 'sc config UmRdpService start= disabled', + 'sc stop SessionEnv', + 'sc config SessionEnv start= disabled', + 'sc stop Server', + 'sc config Server start= disabled', + 'sc stop TeamViewer', + 'sc config TeamViewer start= disabled', + 'sc stop TeamViewer7', + 'sc config start= disabled', + 'sc stop HomeGroupListener', + 'sc config HomeGroupListener start= disabled', + 'sc stop HomeGroupProvider', + 'sc config HomeGroupProvider start= disabled', + 'sc stop AxInstSV', + 'sc config AXInstSV start= disabled', + 'sc stop Netlogon', + 'sc config Netlogon start= disabled', + 'sc stop lltdsvc', + 'sc config lltdsvc start= disabled', + 'sc stop iphlpsvc', + 'sc config iphlpsvc start= disabled', + 'sc stop AdobeARMservice', + 'sc config AdobeARMservice start= disabled' +] + +# Execute stop and disable commands +for command in stop_disable_commands: + subprocess.run(['cmd.exe', '/c', command], check=True) + +# List of commands to start and enable services +start_enable_commands = [ + 'sc start wuauserv', + 'sc config wuauserv start= auto', + 'sc start EventLog', + 'sc config EventLog start= auto', + 'sc start MpsSvc', + 'sc config MpsSvc start= auto', + 'sc start WinDefend', + 'sc config WinDefend start= auto', + 'sc start WdNisSvc', + 'sc config WdNisSvc start= auto', + 'sc start Sense', + 'sc config Sense start= auto', + 'sc start Schedule', + 'sc config Schedule start= auto', + 'sc start SCardSvr', + 'sc config SCardSvr start= auto', + 'sc start ScDeviceEnum', + 'sc config ScDeviceEnum start= auto', + 'sc start SCPolicySvc', + 'sc config SCPolicySvc start= auto', + 'sc start wscsvc', + 'sc config wscsvc start= auto' +] + + + +# Execute start and enable commands +for command in start_enable_commands: + subprocess.run(['cmd.exe', '/c', command], check=True) + From 461b9f40001823f191d6aa2a51729a70bcd54b72 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Tue, 22 Oct 2024 15:10:35 -0500 Subject: [PATCH 59/93] Update Main-Windows-Script.py --- Scripts/Windows/Main-Windows-Script.py | 2 -- 1 file changed, 2 deletions(-) diff --git a/Scripts/Windows/Main-Windows-Script.py b/Scripts/Windows/Main-Windows-Script.py index 6886c97..285203c 100644 --- a/Scripts/Windows/Main-Windows-Script.py +++ b/Scripts/Windows/Main-Windows-Script.py @@ -6,8 +6,6 @@ import subprocess -import os -import fnmatch #enable firewall subprocess.run(["powershell", "Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True"]) From 7316edaea559bdbdf1717cc72781419000030010 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Tue, 22 Oct 2024 15:23:39 -0500 Subject: [PATCH 60/93] Update Main-Windows-Script.py --- Scripts/Windows/Main-Windows-Script.py | 57 ++++++++++++++++++-------- 1 file changed, 40 insertions(+), 17 deletions(-) diff --git a/Scripts/Windows/Main-Windows-Script.py b/Scripts/Windows/Main-Windows-Script.py index 285203c..5863464 100644 --- a/Scripts/Windows/Main-Windows-Script.py +++ b/Scripts/Windows/Main-Windows-Script.py @@ -171,23 +171,6 @@ subprocess.run(["powershell", "-Command", command], check=True) -try: - # Command to run a quick scan using Windows Defender - command = ["powershell", "Start-MpScan", "-ScanType", "QuickScan"] - - # Execute the command - result = subprocess.run(command, capture_output=True, text=True) - - # Check if the command was successful - if result.returncode == 0: - print("Quick scan completed successfully.") - print(result.stdout) - else: - print("Quick scan failed.") - print(result.stderr) -except Exception as e: - print(f"An error occurred: {e}") - # List of commands to stop and disable services might be overlap was coppied and pasted from previous code stop_disable_commands = [ 'sc stop tlntsvr', @@ -386,3 +369,43 @@ for command in start_enable_commands: subprocess.run(['cmd.exe', '/c', command], check=True) + + +try: + # Command to run a quick scan using Windows Defender + command = ["powershell", "Start-MpScan", "-ScanType", "QuickScan"] + + # Execute the command + result = subprocess.run(command, capture_output=True, text=True) + + # Check if the command was successful + if result.returncode == 0: + print("Quick scan completed successfully.") + print(result.stdout) + else: + print("Quick scan failed.") + print(result.stderr) +except Exception as e: + print(f"An error occurred: {e}") + +#check for windows update +try: + print("Checking for updates...") + subprocess.run(["usoclient", "StartScan"], check=True) + print("Update check initiated.") +except subprocess.CalledProcessError as e: + print(f"Failed to check for updates: {e}") + + try: + print("Installing updates...") + subprocess.run(["usoclient", "StartInstall"], check=True) + print("Update installation initiated.") +except subprocess.CalledProcessError as e: + print(f"Failed to install updates: {e}") + +""" +things to add: + account managment + file manangment is a mayber based on if I want to risk deleting cyber patriot files + +""" \ No newline at end of file From 189cf4699eaae4e816407dceac7e8b682cd934cb Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Tue, 22 Oct 2024 15:23:47 -0500 Subject: [PATCH 61/93] Update Main-Windows-Script.py --- Scripts/Windows/Main-Windows-Script.py | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/Scripts/Windows/Main-Windows-Script.py b/Scripts/Windows/Main-Windows-Script.py index 5863464..a762803 100644 --- a/Scripts/Windows/Main-Windows-Script.py +++ b/Scripts/Windows/Main-Windows-Script.py @@ -390,22 +390,22 @@ #check for windows update try: - print("Checking for updates...") - subprocess.run(["usoclient", "StartScan"], check=True) - print("Update check initiated.") + print("Checking for updates...") + subprocess.run(["usoclient", "StartScan"], check=True) + print("Update check initiated.") except subprocess.CalledProcessError as e: - print(f"Failed to check for updates: {e}") + print(f"Failed to check for updates: {e}") - try: - print("Installing updates...") - subprocess.run(["usoclient", "StartInstall"], check=True) - print("Update installation initiated.") +try: + print("Installing updates...") + subprocess.run(["usoclient", "StartInstall"], check=True) + print("Update installation initiated.") except subprocess.CalledProcessError as e: - print(f"Failed to install updates: {e}") + print(f"Failed to install updates: {e}") """ things to add: account managment - file manangment is a mayber based on if I want to risk deleting cyber patriot files - + file manangment is a maybe based on if I want to risk deleting cyber patriot files + malware removal """ \ No newline at end of file From d6d6500a1f9695525f812f81fb9370ad49e19b7f Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Fri, 25 Oct 2024 09:16:34 -0500 Subject: [PATCH 62/93] did stuff --- .idea/.gitignore | 8 ++++++++ .idea/WAFFLEplus.iml | 8 ++++++++ .idea/inspectionProfiles/profiles_settings.xml | 6 ++++++ .idea/misc.xml | 4 ++++ .idea/modules.xml | 8 ++++++++ .idea/vcs.xml | 6 ++++++ 6 files changed, 40 insertions(+) create mode 100644 .idea/.gitignore create mode 100644 .idea/WAFFLEplus.iml create mode 100644 .idea/inspectionProfiles/profiles_settings.xml create mode 100644 .idea/misc.xml create mode 100644 .idea/modules.xml create mode 100644 .idea/vcs.xml diff --git a/.idea/.gitignore b/.idea/.gitignore new file mode 100644 index 0000000..13566b8 --- /dev/null +++ b/.idea/.gitignore @@ -0,0 +1,8 @@ +# Default ignored files +/shelf/ +/workspace.xml +# Editor-based HTTP Client requests +/httpRequests/ +# Datasource local storage ignored files +/dataSources/ +/dataSources.local.xml diff --git a/.idea/WAFFLEplus.iml b/.idea/WAFFLEplus.iml new file mode 100644 index 0000000..d0876a7 --- /dev/null +++ b/.idea/WAFFLEplus.iml @@ -0,0 +1,8 @@ + + + + + + + + \ No newline at end of file diff --git a/.idea/inspectionProfiles/profiles_settings.xml b/.idea/inspectionProfiles/profiles_settings.xml new file mode 100644 index 0000000..105ce2d --- /dev/null +++ b/.idea/inspectionProfiles/profiles_settings.xml @@ -0,0 +1,6 @@ + + + + \ No newline at end of file diff --git a/.idea/misc.xml b/.idea/misc.xml new file mode 100644 index 0000000..060d2c5 --- /dev/null +++ b/.idea/misc.xml @@ -0,0 +1,4 @@ + + + + \ No newline at end of file diff --git a/.idea/modules.xml b/.idea/modules.xml new file mode 100644 index 0000000..b648862 --- /dev/null +++ b/.idea/modules.xml @@ -0,0 +1,8 @@ + + + + + + + + \ No newline at end of file diff --git a/.idea/vcs.xml b/.idea/vcs.xml new file mode 100644 index 0000000..35eb1dd --- /dev/null +++ b/.idea/vcs.xml @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file From 7dd1215283e01b9c88d170c18241684a0d72bb6e Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Fri, 25 Oct 2024 09:45:28 -0500 Subject: [PATCH 63/93] created stuff --- .idea/misc.xml | 3 +++ .../Windows/{ => MaxwellsWindowsScript}/Main-Windows-Script.py | 0 Scripts/Windows/MaxwellsWindowsScript/accountManager.py | 0 3 files changed, 3 insertions(+) rename Scripts/Windows/{ => MaxwellsWindowsScript}/Main-Windows-Script.py (100%) create mode 100644 Scripts/Windows/MaxwellsWindowsScript/accountManager.py diff --git a/.idea/misc.xml b/.idea/misc.xml index 060d2c5..db8786c 100644 --- a/.idea/misc.xml +++ b/.idea/misc.xml @@ -1,4 +1,7 @@ + + \ No newline at end of file diff --git a/Scripts/Windows/Main-Windows-Script.py b/Scripts/Windows/MaxwellsWindowsScript/Main-Windows-Script.py similarity index 100% rename from Scripts/Windows/Main-Windows-Script.py rename to Scripts/Windows/MaxwellsWindowsScript/Main-Windows-Script.py diff --git a/Scripts/Windows/MaxwellsWindowsScript/accountManager.py b/Scripts/Windows/MaxwellsWindowsScript/accountManager.py new file mode 100644 index 0000000..e69de29 From edeef3dd65adebcb0702c16d16815ddbd356b29a Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Fri, 25 Oct 2024 11:45:43 -0500 Subject: [PATCH 64/93] added files --- .github/.gitignore | 2 + ...countManager.py => account-management.log} | 0 .../MaxwellsWindowsScript/accountChecker.py | 2 + .../MaxwellsWindowsScript/accountManagment.py | 241 ++++++++++++++++++ .../accountManagmentReadMe.txt | 33 +++ 5 files changed, 278 insertions(+) create mode 100644 .github/.gitignore rename Scripts/Windows/MaxwellsWindowsScript/{accountManager.py => account-management.log} (100%) create mode 100644 Scripts/Windows/MaxwellsWindowsScript/accountChecker.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/accountManagment.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/accountManagmentReadMe.txt diff --git a/.github/.gitignore b/.github/.gitignore new file mode 100644 index 0000000..7ee4e66 --- /dev/null +++ b/.github/.gitignore @@ -0,0 +1,2 @@ + +*.log \ No newline at end of file diff --git a/Scripts/Windows/MaxwellsWindowsScript/accountManager.py b/Scripts/Windows/MaxwellsWindowsScript/account-management.log similarity index 100% rename from Scripts/Windows/MaxwellsWindowsScript/accountManager.py rename to Scripts/Windows/MaxwellsWindowsScript/account-management.log diff --git a/Scripts/Windows/MaxwellsWindowsScript/accountChecker.py b/Scripts/Windows/MaxwellsWindowsScript/accountChecker.py new file mode 100644 index 0000000..139597f --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/accountChecker.py @@ -0,0 +1,2 @@ + + diff --git a/Scripts/Windows/MaxwellsWindowsScript/accountManagment.py b/Scripts/Windows/MaxwellsWindowsScript/accountManagment.py new file mode 100644 index 0000000..98c1002 --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/accountManagment.py @@ -0,0 +1,241 @@ +import ctypes, sys +import subprocess +from getpass import getpass +import logging +from datetime import datetime + +# Set up logging +logging.basicConfig(filename='account-management.log', level=logging.INFO) + +# log account creation +now = datetime.now() + + +# Checks if the user running the script has administrator privileges +def is_admin(): + try: + return ctypes.windll.shell32.IsUserAnAdmin() + except: + return False + + +def create_account(): + """Creates local accounts""" + username = input("Enter username: ") + password = check_password() + + create_account_cmd = f"net user {username} {password} /add" + run_cmd(create_account_cmd, f"User {username} created successfully.", f"Error creating user {username}.", + f"Create user {username} {now}", f"Failed to create {username} {now}") + + +def create_admin(): + """Creates local admin accounts""" + account_name = input("What account do you want to make an admin: ") + make_admin_cmd = f"net localgroup administrators {account_name} /add" + + run_cmd(make_admin_cmd, f"{account_name} is now apart of administrator group", f"Error making {account_name} admin", + f" {account_name} is now administrator {now}", f"Failed to create {account_name} {now}") + + +def assign_account_to_group(): + """Assign account to group""" + get_groups_cmd = "net localgroup" + + run_cmd(get_groups_cmd, "All groups are listed", "Error getting groups", f"Get all users {now}", + f"Failed to get all user {now}") + + +def remove_account_from_group(): + """Remove user from assigned group""" + print("Remove user from group") + + username = input("Enter username: ") + group = input(f"Remove {username} from: ") + command = f"net localgroup \"{username}\" " f"\"{group}\" /DELETE" + + run_cmd(command, f"Removed {username} from {group}", f"Failed to remove {username} from {group}", + f"Successfully removed {username} from {group} {now}") + + +def check_password(): + """Verifies password to create account""" + password = getpass("Enter password for account: ") + check_password = getpass("Enter password again: ") + + while password != check_password: + print("Passwords do not match") + password = getpass("Enter password for account: ") + check_password = getpass("Enter password again: ") + + return password + + +def delete_account(): + """Deletes local account off computer""" + command = "net user" + run_cmd(command, "Got all users successfully", "Failed to get all users", f"All users {now}", + f"Failed to get all {now}") + + # Removes \n and other text from the net user command + try: + all_accounts = subprocess.run(command, check=True, shell=True, stdout=subprocess.PIPE, stderr=subprocess.PIPE) + + if all_accounts.returncode == 0: + print("All Local Accounts are listed") + for accounts in all_accounts.stdout.decode().splitlines(): + if accounts: + print(accounts) + else: + print(f"Error getting accounts") + except subprocess.CalledProcessError as e: + print(f"Error getting all accounts.") + print(e.stderr.decode()) + + username = input("Account to delete: ") + delete_account_command = f"net user {username} /DELETE" + + run_cmd(delete_account_command, "Account successfully deleted", "Error deleting account", + f"Successfully delete {username} account", f"Failed to delete {username}") + + +def enable_disable_account(): + """Enables or Disable accounts on machine""" + ask_to_enable_disable = input("Would you like to enable or disable: ") + username = input("Enter the username: ") + enable_account_command = f"net user {username} /ACTIVE:yes" + disable_account_command = f"net user {username} /ACTIVE:no" + + if ask_to_enable_disable == "enable": + try: + enable_account = subprocess.run(enable_account_command, check=True, shell=True, stdout=subprocess.PIPE, + stderr=subprocess.PIPE) + + if enable_account.returncode == 0: + print(f"{username} was successfully enabled") + else: + print("Failed to enable account") + logging.info(f"Failed to enable account: {username} {now}") + except subprocess.CalledProcessError as e: + print("An error has happened when enabling account") + print(e.stderr.decode()) + + if ask_to_enable_disable == "disable": + try: + disable_account = subprocess.run(disable_account_command, check=True, shell=True, stdout=subprocess.PIPE, + stderr=subprocess.PIPE) + + if disable_account.returncode == 0: + print(f"{username} was successfully disabled") + else: + print("Failed to disabled account") + logging.info(f"Failed to disable account {username} {now}") + except subprocess.CalledProcessError as e: + print("An error has happened when disabling account") + print(e.stderr.decode()) + + +def disable_defualt_accounts(): + disable_guest_account = "net user Guest /active:no" + disable_admin_account = "net user Administrator /active:no" + + run_cmd(disable_guest_account, "Guest account is disabled", "Failed to disable Guest account", + f"Guest is now disabled {now}", f"Failed to disable Guest account {now}") + run_cmd(disable_admin_account, "Administrator account is disabled", "Failed to disable Administrator account", + f"Administrator is now disabled {now}", f"Failed to disable Administrator account {now}") + + +def login_times(): + """Allows user to setup login restrictions for accounts""" + username = input("Enter account name: ") + days = input(f"Enter the days for {username} (ex M-F): ") + times = input(f"Enter the times for the {username} (9am-5pm)") + + command = f"net user {username} /times:{days},{times}" + + run_cmd(command, f"{username} is now active during {days} and {times}", "Failed to setup login times", + f"{username} can now login during {days} {times} {now}") + + +def all_groups_for_user(): + print("See all groups that belong to the user") + username = input("Enter username: ") + command = f"net user {username} | findstr \"Local Group Memberships\"" + + run_cmd(command, "Got all user groups", "Failed to get all user assigned groups", + f"{username} asspcoated groups listed {now}", + f"Failed to get all {username} associated groups listed {now} ") + + +def run_cmd(cmd, success_msg, error_msg, success_log_msg, failed_log_msg): + try: + result = subprocess.run(cmd, check=True, shell=True, stdout=subprocess.PIPE, stderr=subprocess.PIPE) + + if result.returncode == 0: + print(success_msg) + logging.info(success_log_msg) + else: + print(error_msg) + print(result.stderr.decode()) + logging.critical(failed_log_msg) + + except subprocess.CalledProcessError as e: + print(error_msg) + print(e.stderr.decode()) + logging.error(failed_log_msg) + + +if is_admin(): + # Code of your program here + try: + print("ctrl-c to quit") + + while True: + print("1. Create account \t\t 2. Make account admin") + print("3. Manually add to group \t 4. Delete account") + print("5. Enable/Disable Accounts \t 6. Disable defualt accounts") + print("7. Listed associated groups to user 8. quit") + print("-" * 50) + + # Valildates the user entered a number + try: + choice = int(input("Your choice: ")) + except ValueError: + print("Please enter a number") + continue + + options = { + 1: create_account, + 2: create_admin, + 3: assign_account_to_group, + 4: delete_account, + 5: enable_disable_account, + 6: disable_defualt_accounts, + 7: all_groups_for_user, + 8: quit, + } + + # Runs the funciton based of user input + if choice in options: + options[choice]() + else: + print("Please enter a valid choice (1-6)") + + # Askes if the user want to change their choice + switch_choice = input("Do you want to switch choice? (y/n) ") + if switch_choice.lower() == "y": + if choice == 1 or choice == 2 or choice == 3: + continue + elif switch_choice.lower() == "n": + while True: + options[choice]() + else: + break + + except KeyboardInterrupt: + quit() +else: + # Re-run the program with admin rights + ctypes.windll.shell32.ShellExecuteW(None, "runas", sys.executable, " ".join(sys.argv), None, 1) + +input("Press enter to exit") \ No newline at end of file diff --git a/Scripts/Windows/MaxwellsWindowsScript/accountManagmentReadMe.txt b/Scripts/Windows/MaxwellsWindowsScript/accountManagmentReadMe.txt new file mode 100644 index 0000000..60d6ced --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/accountManagmentReadMe.txt @@ -0,0 +1,33 @@ +Windows User Management +This Python script provides functions to manage local user accounts on a Windows machine. This script requires administrative privileges to run. + +Prerequisites +This script requires Python 3.6 or higher to be installed on the Windows machine. Administrative privileges are also required to create, delete, or modify user accounts. + +Functions +The following functions are provided by this script: + +create_account(): This function creates a standard user account. The user is prompted to enter a username and password for the new account. + +create_admin(): This function adds an existing user account to the Administrators group. + +assign_account_to_group(): This function adds an existing user account to a specified group. + +delete_account(): This function deletes an existing user account. + +enable_disable_account(): This function enables or disables an existing user account. + + +Navigate to the directory containing the script. + +Run the script using the following command: + +Copy code +python Windows-User-Account-Management.py +Follow the prompts to perform user management tasks. + +Example +To create a new user account, run the script and choose the Create Account option. Enter a username and password for the new account when prompted. The script will create the account and provide a success message if the operation is successful. + +Disclaimer +Use this script at your own risk. The author is not responsible for any damages or losses that may result from the use of this script. \ No newline at end of file From e196ffe486974e39d4884ae8a62f549cfbe08af8 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 28 Oct 2024 10:10:15 -0500 Subject: [PATCH 65/93] split main into multiple files --- .../account_management.py | 13 ++++++++++ .../MaxwellsWindowsScript/audit_policies.py | 22 ++++++++++++++++ .../MaxwellsWindowsScript/defender_updates.py | 26 +++++++++++++++++++ .../MaxwellsWindowsScript/firewall_config.py | 8 ++++++ .../password_policies.py | 18 +++++++++++++ .../service_manaement.py | 16 ++++++++++++ .../software_management.py | 26 +++++++++++++++++++ .../MaxwellsWindowsScript/uac_settings.py | 8 ++++++ 8 files changed, 137 insertions(+) create mode 100644 Scripts/Windows/MaxwellsWindowsScript/account_management.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/audit_policies.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/defender_updates.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/firewall_config.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/password_policies.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/service_manaement.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/software_management.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/uac_settings.py diff --git a/Scripts/Windows/MaxwellsWindowsScript/account_management.py b/Scripts/Windows/MaxwellsWindowsScript/account_management.py new file mode 100644 index 0000000..4c64633 --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/account_management.py @@ -0,0 +1,13 @@ +import subprocess + +def disable_accounts(): + commands = [ + 'net user admin /active:no', + 'net user guest /active:no' + ] + for command in commands: + subprocess.run(command, shell=True, check=True) + print(f"{command} executed") + +if __name__ == "__main__": + disable_accounts() diff --git a/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py b/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py new file mode 100644 index 0000000..64d306a --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py @@ -0,0 +1,22 @@ +import subprocess + +def configure_audit_policies(): + audit_policies = [ + "Audit account logon events", + "Audit account management", + "Audit directory service access", + "Audit logon events", + "Audit object access", + "Audit policy change", + "Audit privilege use", + "Audit process tracking", + "Audit system events" + ] + command_template = 'auditpol /set /subcategory:"{}" /success:enable /failure:enable' + for policy in audit_policies: + command = command_template.format(policy) + subprocess.run(command, shell=True, check=True) + print(f"{command} executed") + +if __name__ == "__main__": + configure_audit_policies() diff --git a/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py b/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py new file mode 100644 index 0000000..6eda1ad --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py @@ -0,0 +1,26 @@ +import subprocess + +def run_windows_defender_scan(): + command = ["powershell", "Start-MpScan", "-ScanType", "QuickScan"] + result = subprocess.run(command, capture_output=True, text=True) + if result.returncode == 0: + print("Quick scan completed successfully.") + print(result.stdout) + else: + print("Quick scan failed.") + print(result.stderr) + +def check_install_updates(): + try: + print("Checking for updates...") + subprocess.run(["usoclient", "StartScan"], check=True) + print("Update check initiated.") + print("Installing updates...") + subprocess.run(["usoclient", "StartInstall"], check=True) + print("Update installation initiated.") + except subprocess.CalledProcessError as e: + print(f"Failed to check or install updates: {e}") + +if __name__ == "__main__": + run_windows_defender_scan() + check_install_updates() diff --git a/Scripts/Windows/MaxwellsWindowsScript/firewall_config.py b/Scripts/Windows/MaxwellsWindowsScript/firewall_config.py new file mode 100644 index 0000000..6cc2a26 --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/firewall_config.py @@ -0,0 +1,8 @@ +import subprocess + +def enable_firewall(): + subprocess.run(["powershell", "Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True"]) + print("Firewall enabled.") + +if __name__ == "__main__": + enable_firewall() diff --git a/Scripts/Windows/MaxwellsWindowsScript/password_policies.py b/Scripts/Windows/MaxwellsWindowsScript/password_policies.py new file mode 100644 index 0000000..938d720 --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/password_policies.py @@ -0,0 +1,18 @@ +import subprocess + +def configure_password_policies(): + password_policies = [ + "net accounts /minpwlen:8", + "net accounts /maxpwage:30", + "net accounts /minpwage:1", + "net accounts /uniquepw:5", + "net accounts /lockoutthreshold:5", + "net accounts /lockoutduration:30", + "net accounts /lockoutwindow:30" + ] + for policy in password_policies: + subprocess.run(policy, shell=True, check=True) + print(f"{policy} executed") + +if __name__ == "__main__": + configure_password_policies() diff --git a/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py b/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py new file mode 100644 index 0000000..0936f1d --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py @@ -0,0 +1,16 @@ +import subprocess + +def manage_services(): + services_to_disable = [ + "TermService", "SharedAccess", "UmRdpService", "ftpsvc", + "RemoteRegistry", "SessionEnv", "SSDPSRV", "upnphost", "W3SVC", + "sshd" + ] + for service in services_to_disable: + print(f"Stopping {service}") + subprocess.run(f'sc stop {service}', shell=True, check=True) + subprocess.run(f'sc config {service} start= disabled', shell=True, check=True) + print("Disabled and stopped unnecessary services.") + +if __name__ == "__main__": + manage_services() diff --git a/Scripts/Windows/MaxwellsWindowsScript/software_management.py b/Scripts/Windows/MaxwellsWindowsScript/software_management.py new file mode 100644 index 0000000..f4a8b8d --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/software_management.py @@ -0,0 +1,26 @@ +import subprocess + +def uninstall_malicious_software(): + software_list = ["Wireshark", "Netcap", "CCleaner"] + powershell_script = """ + $softwareList = @{software_list} + $installedSoftware = Get-WmiObject -Class Win32_Product + foreach ($software in $softwareList) {{ + $app = $installedSoftware | Where-Object {{ $_.Name -like "*$software*" }} + if ($app) {{ + try {{ + $app.Uninstall() + Write-Output "Uninstalled: $($app.Name)" + }} catch {{ + Write-Output "Error uninstalling $($app.Name): $_" + }} + }} else {{ + Write-Output "$software is not installed." + }} + }} + """.format(software_list=", ".join([f'"{software}"' for software in software_list])) + subprocess.run(["powershell", "-Command", powershell_script], check=True) + print("Malicious software uninstallation attempted.") + +if __name__ == "__main__": + uninstall_malicious_software() diff --git a/Scripts/Windows/MaxwellsWindowsScript/uac_settings.py b/Scripts/Windows/MaxwellsWindowsScript/uac_settings.py new file mode 100644 index 0000000..a4abff5 --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/uac_settings.py @@ -0,0 +1,8 @@ +import subprocess + +def configure_uac(): + subprocess.run('powershell.exe -Command "Set-ItemProperty -Path HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System -Name ConsentPromptBehaviorAdmin -Value 2"', shell=True, check=True) + print("UAC settings updated.") + +if __name__ == "__main__": + configure_uac() From cecff366313a845b6d60ec2da37dd3649dc908e9 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 28 Oct 2024 10:10:39 -0500 Subject: [PATCH 66/93] Delete Main-Windows-Script.py --- .../Main-Windows-Script.py | 411 ------------------ 1 file changed, 411 deletions(-) delete mode 100644 Scripts/Windows/MaxwellsWindowsScript/Main-Windows-Script.py diff --git a/Scripts/Windows/MaxwellsWindowsScript/Main-Windows-Script.py b/Scripts/Windows/MaxwellsWindowsScript/Main-Windows-Script.py deleted file mode 100644 index a762803..0000000 --- a/Scripts/Windows/MaxwellsWindowsScript/Main-Windows-Script.py +++ /dev/null @@ -1,411 +0,0 @@ -""" -This is the main script for Windows. -All task for this script will be pulled from the windows cyberPatriot checklist. -order of the task is not yet determined.(possibly no order) -""" - - -import subprocess - -#enable firewall -subprocess.run(["powershell", "Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True"]) -print("Firewall enabled.") - -print("audit policies") -# List of audit policies to configure -audit_policies = [ - "Audit account logon events", - "Audit account management", - "Audit directory service access", - "Audit logon events", - "Audit object access", - "Audit policy change", - "Audit privilege use", - "Audit process tracking", - "Audit system events" -] - -# Command template to set audit policy -command_template = 'auditpol /set /subcategory:"{}" /success:enable /failure:enable' - -# Loop through each policy and set it to log both successes and failures -for policy in audit_policies: - command = command_template.format(policy) - subprocess.run(command, shell=True, check=True) - print(command) - -print("Audit policies updated to log both successes and failures.") - -print("password policies") -#change password policies -password_policies = [ - "net accounts /minpwlen:8", # Minimum password length - "net accounts /maxpwage:30", # Maximum password age (days) - "net accounts /minpwage:1", # Minimum password age (days) - "net accounts /uniquepw:5", # Number of unique passwords before reuse - "net accounts /lockoutthreshold:5", # Account lockout threshold - "net accounts /lockoutduration:30", # Account lockout duration (minutes) - "net accounts /lockoutwindow:30" # Reset account lockout counter after (minutes) -] - -for policy in password_policies: - subprocess.run(policy, shell=True, check=True) - print(policy) -print("Password policies updated.") -#change UAC (user account control) settings -print("UAC settings") -subprocess.run('powershell.exe -Command "Set-ItemProperty -Path HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System -Name ConsentPromptBehaviorAdmin -Value 2"', shell = True, check = True) -print("UAC settings updated.") - -#disable admin and guest account -print("Disabling guest and admin account") -commands = [ - 'net user admin /active:no', - 'net user guest /active:no' -] - -for command in commands: - subprocess.run(command, shell=True, check=True) - -print("Admin and Guest accounts have been disabled.") - - -#remove malicous software -# List of software to uninstall -software_list = ["Wireshark", "Netcap", "CCleaner"] - -# PowerShell script to uninstall software -powershell_script = """ -$softwareList = @{} -$installedSoftware = Get-WmiObject -Class Win32_Product - -foreach ($software in $softwareList) {{ - $app = $installedSoftware | Where-Object {{ $_.Name -like "*$software*" }} - if ($app) {{ - try {{ - $app.Uninstall() - Write-Output "Uninstalled: $($app.Name)" - }} catch {{ - Write-Output "Error uninstalling $($app.Name): $_" - }} - }} else {{ - Write-Output "$software is not installed." - }} -}} -""".format(", ".join([f'"{software}"' for software in software_list])) - -# Run the PowerShell script -subprocess.run(["powershell", "-Command", powershell_script], check=True) - -# PowerShell command to update Google Chrome -powershell_command = """ -$chromePath = "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe" -if (Test-Path $chromePath) { - $updateCommand = "$chromePath --check-for-update-interval=1" - Start-Process -FilePath "cmd.exe" -ArgumentList "/c", $updateCommand -Verb RunAs - Write-Output "Google Chrome update initiated." -} else { - Write-Output "Google Chrome is not installed." -} -""" - -# Run the PowerShell command -subprocess.run(["powershell", "-Command", powershell_command], check=True) - -# PowerShell command to update Firefox -powershell_command_firefox = """ -$firefoxPath = "C:\\Program Files\\Mozilla Firefox\\firefox.exe" -if (Test-Path $firefoxPath) { - $updateCommand = "$firefoxPath -silent -update" - Start-Process -FilePath "cmd.exe" -ArgumentList "/c", $updateCommand -Verb RunAs - Write-Output "Mozilla Firefox update initiated." -} else { - Write-Output "Mozilla Firefox is not installed." -} -""" - -# Run the PowerShell command for Firefox -subprocess.run(["powershell", "-Command", powershell_command_firefox], check=True) - -# List of services to stop and disable -services = [ - "TermService", # RDP - "SharedAccess", # ICS - "UmRdpService", # RDP UserMode - "ftpsvc", # Windows FTP service - "RemoteRegistry", # Remote Registry - "SessionEnv", # RD Configuration - "SSDPSRV", # SSDP Discovery - "upnphost", # UPnP Device Host - "TermService", # Remote Desktop - "W3SVC", # WWW Publishing Service - "TermService", # remote desktop - "sshd" # ssh -] - -for service in services: - print(f"Stopping {service} service") - subprocess.run(f'sc stop {service}', shell=True, check=True) - print(f"Disabling {service} service") - subprocess.run(f'sc config {service} start= disabled', shell=True, check=True) - -# Disable remote desktop -print("Disabling Remote Desktop") -subprocess.run('reg add "HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 1 /f', shell=True, check=True) -print("Remote Desktop has been disabled.") - -# List of PowerShell commands to block the specified ports -commands = [ - 'New-NetFirewallRule -DisplayName "Block RDP" -Direction Inbound -LocalPort 3389 -Protocol TCP -Action Block', - 'New-NetFirewallRule -DisplayName "Block SSH" -Direction Inbound -LocalPort 22 -Protocol TCP -Action Block', - 'New-NetFirewallRule -DisplayName "Block TelNet" -Direction Inbound -LocalPort 23 -Protocol TCP -Action Block', - 'New-NetFirewallRule -DisplayName "Block SNMP 161" -Direction Inbound -LocalPort 161 -Protocol UDP -Action Block', - 'New-NetFirewallRule -DisplayName "Block SNMP 162" -Direction Inbound -LocalPort 162 -Protocol UDP -Action Block', - 'New-NetFirewallRule -DisplayName "Block LDAP" -Direction Inbound -LocalPort 389 -Protocol TCP -Action Block', - 'New-NetFirewallRule -DisplayName "Block FTP Command" -Direction Inbound -LocalPort 21 -Protocol TCP -Action Block', - 'New-NetFirewallRule -DisplayName "Block FTP Data" -Direction Inbound -LocalPort 20 -Protocol TCP -Action Block' -] - -# Execute each command using subprocess.run -for command in commands: - subprocess.run(["powershell", "-Command", command], check=True) - - -# List of commands to stop and disable services might be overlap was coppied and pasted from previous code -stop_disable_commands = [ - 'sc stop tlntsvr', - 'sc config tlntsvr start= disabled', - 'sc stop msftpsvc', - 'sc config msftpsvc start= disabled', - 'sc stop snmptrap', - 'sc config snmptrap start= disabled', - 'sc stop ssdpsrv', - 'sc config ssdpsrv start= disabled', - 'sc stop termservice', - 'sc config termservice start= disabled', - 'sc stop sessionenv', - 'sc config sessionenv start= disabled', - 'sc stop remoteregistry', - 'sc config remoteregistry start= disabled', - 'sc stop Messenger', - 'sc config Messenger start= disabled', - 'sc stop upnphos', - 'sc config upnphos start= disabled', - 'sc stop WAS', - 'sc config WAS start= disabled', - 'sc stop RemoteAccess', - 'sc config RemoteAccess start= disabled', - 'sc stop mnmsrvc', - 'sc config mnmsrvc start= disabled', - 'sc stop NetTcpPortSharing', - 'sc config NetTcpPortSharing start= disabled', - 'sc stop RasMan', - 'sc config RasMan start= disabled', - 'sc stop TabletInputService', - 'sc config TabletInputService start= disabled', - 'sc stop RpcSs', - 'sc config RpcSs start= disabled', - 'sc stop SENS', - 'sc config SENS start= disabled', - 'sc stop EventSystem', - 'sc config EventSystem start= disabled', - 'sc stop XblAuthManager', - 'sc config XblAuthManager start= disabled', - 'sc stop XblGameSave', - 'sc config XblGameSave start= disabled', - 'sc stop XboxGipSvc', - 'sc config XboxGipSvc start= disabled', - 'sc stop xboxgip', - 'sc config xboxgip start= disabled', - 'sc stop xbgm', - 'sc config xbgm start= disabled', - 'sc stop SysMain', - 'sc config SysMain start= disabled', - 'sc stop seclogon', - 'sc config seclogon start= disabled', - 'sc stop TapiSrv', - 'sc config TapiSrv start= disabled', - 'sc stop p2pimsvc', - 'sc config p2pimsvc start= disabled', - 'sc stop simptcp', - 'sc config simptcp start= disabled', - 'sc stop fax', - 'sc config fax start= disabled', - 'sc stop Msftpsvc', - 'sc config Msftpsvc start= disabled', - 'sc stop iprip', - 'sc config iprip start= disabled', - 'sc stop ftpsvc', - 'sc config ftpsvc start= disabled', - 'sc stop RasAuto', - 'sc config RasAuto start= disabled', - 'sc stop W3svc', - 'sc config W3svc start= disabled', - 'sc stop Smtpsvc', - 'sc config Smtpsvc start= disabled', - 'sc stop Dfs', - 'sc config Dfs start= disabled', - 'sc stop TrkWks', - 'sc config TrkWks start= disabled', - 'sc stop MSDTC', - 'sc config MSDTC start= disabled', - 'sc stop ERSvc', - 'sc config ERSvc start= disabled', - 'sc stop NtFrs', - 'sc config NtFrs start= disabled', - 'sc stop Iisadmin', - 'sc config Iisadmin start= disabled', - 'sc stop IsmServ', - 'sc config IsmServ start= disabled', - 'sc stop WmdmPmSN', - 'sc config WmdmPmSN start= disabled', - 'sc stop helpsvc', - 'sc config helpsvc start= disabled', - 'sc stop Spooler', - 'sc config Spooler start= disabled', - 'sc stop RDSessMgr', - 'sc config RDSessMgr start= disabled', - 'sc stop RSoPProv', - 'sc config RSoPProv start= disabled', - 'sc stop SCardSvr', - 'sc config SCardSvr start= disabled', - 'sc stop lanmanserver', - 'sc config lanmanserver start= disabled', - 'sc stop Sacsvr', - 'sc config Sacsvr start= disabled', - 'sc stop TermService', - 'sc config TermService start= disabled', - 'sc stop uploadmgr', - 'sc config uploadmgr start= disabled', - 'sc stop VDS', - 'sc config VDS start= disabled', - 'sc stop VSS', - 'sc config VSS start= disabled', - 'sc stop WINS', - 'sc config WINS start= disabled', - 'sc stop CscService', - 'sc config CscService start= disabled', - 'sc stop hidserv', - 'sc config hidserv start= disabled', - 'sc stop IPBusEnum', - 'sc config IPBusEnum start= disabled', - 'sc stop PolicyAgent', - 'sc config PolicyAgent start= disabled', - 'sc stop SharedAccess', - 'sc config SharedAccess start= disabled', - 'sc stop SSDPSRV', - 'sc config SSDPSRV start= disabled', - 'sc stop Themes', - 'sc config Themes start= disabled', - 'sc stop upnphost', - 'sc config upnphost start= disabled', - 'sc stop nfssvc', - 'sc config nfssvc start= disabled', - 'sc stop nfsclnt', - 'sc config nfsclnt start= disabled', - 'sc stop MSSQLServerADHelper', - 'sc config MSSQLServerADHelper start= disabled', - 'sc stop SharedAccess', - 'sc config SharedAccess start= disabled', - 'sc stop UmRdpService', - 'sc config UmRdpService start= disabled', - 'sc stop SessionEnv', - 'sc config SessionEnv start= disabled', - 'sc stop Server', - 'sc config Server start= disabled', - 'sc stop TeamViewer', - 'sc config TeamViewer start= disabled', - 'sc stop TeamViewer7', - 'sc config start= disabled', - 'sc stop HomeGroupListener', - 'sc config HomeGroupListener start= disabled', - 'sc stop HomeGroupProvider', - 'sc config HomeGroupProvider start= disabled', - 'sc stop AxInstSV', - 'sc config AXInstSV start= disabled', - 'sc stop Netlogon', - 'sc config Netlogon start= disabled', - 'sc stop lltdsvc', - 'sc config lltdsvc start= disabled', - 'sc stop iphlpsvc', - 'sc config iphlpsvc start= disabled', - 'sc stop AdobeARMservice', - 'sc config AdobeARMservice start= disabled' -] - -# Execute stop and disable commands -for command in stop_disable_commands: - subprocess.run(['cmd.exe', '/c', command], check=True) - -# List of commands to start and enable services -start_enable_commands = [ - 'sc start wuauserv', - 'sc config wuauserv start= auto', - 'sc start EventLog', - 'sc config EventLog start= auto', - 'sc start MpsSvc', - 'sc config MpsSvc start= auto', - 'sc start WinDefend', - 'sc config WinDefend start= auto', - 'sc start WdNisSvc', - 'sc config WdNisSvc start= auto', - 'sc start Sense', - 'sc config Sense start= auto', - 'sc start Schedule', - 'sc config Schedule start= auto', - 'sc start SCardSvr', - 'sc config SCardSvr start= auto', - 'sc start ScDeviceEnum', - 'sc config ScDeviceEnum start= auto', - 'sc start SCPolicySvc', - 'sc config SCPolicySvc start= auto', - 'sc start wscsvc', - 'sc config wscsvc start= auto' -] - - - -# Execute start and enable commands -for command in start_enable_commands: - subprocess.run(['cmd.exe', '/c', command], check=True) - - - -try: - # Command to run a quick scan using Windows Defender - command = ["powershell", "Start-MpScan", "-ScanType", "QuickScan"] - - # Execute the command - result = subprocess.run(command, capture_output=True, text=True) - - # Check if the command was successful - if result.returncode == 0: - print("Quick scan completed successfully.") - print(result.stdout) - else: - print("Quick scan failed.") - print(result.stderr) -except Exception as e: - print(f"An error occurred: {e}") - -#check for windows update -try: - print("Checking for updates...") - subprocess.run(["usoclient", "StartScan"], check=True) - print("Update check initiated.") -except subprocess.CalledProcessError as e: - print(f"Failed to check for updates: {e}") - -try: - print("Installing updates...") - subprocess.run(["usoclient", "StartInstall"], check=True) - print("Update installation initiated.") -except subprocess.CalledProcessError as e: - print(f"Failed to install updates: {e}") - -""" -things to add: - account managment - file manangment is a maybe based on if I want to risk deleting cyber patriot files - malware removal -""" \ No newline at end of file From c76f31210651495a4e74e18f5703bb04d0d94bb3 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 28 Oct 2024 10:12:34 -0500 Subject: [PATCH 67/93] Delete account_management.py --- .../MaxwellsWindowsScript/account_management.py | 13 ------------- 1 file changed, 13 deletions(-) delete mode 100644 Scripts/Windows/MaxwellsWindowsScript/account_management.py diff --git a/Scripts/Windows/MaxwellsWindowsScript/account_management.py b/Scripts/Windows/MaxwellsWindowsScript/account_management.py deleted file mode 100644 index 4c64633..0000000 --- a/Scripts/Windows/MaxwellsWindowsScript/account_management.py +++ /dev/null @@ -1,13 +0,0 @@ -import subprocess - -def disable_accounts(): - commands = [ - 'net user admin /active:no', - 'net user guest /active:no' - ] - for command in commands: - subprocess.run(command, shell=True, check=True) - print(f"{command} executed") - -if __name__ == "__main__": - disable_accounts() From ce96734cf14b953490b32ac7c1a5ef0a3b55a6fa Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 28 Oct 2024 15:33:41 -0500 Subject: [PATCH 68/93] Create file_cleaner.py --- Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py | 0 1 file changed, 0 insertions(+), 0 deletions(-) create mode 100644 Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py new file mode 100644 index 0000000..e69de29 From a09daed7610d586f5c442405578bd3e958f352c7 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 28 Oct 2024 15:54:29 -0500 Subject: [PATCH 69/93] Update file_cleaner.py --- .../MaxwellsWindowsScript/file_cleaner.py | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index e69de29..0c13f2d 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -0,0 +1,22 @@ +#delete files of certain types in all directories except for cyber patriot personel directory +#Can probably localize it to program files directory and users directory (research probably) +import os + +#list all file types to delete +fileTypes = [".jpg", ".png", ".aac", ".ac3", ".avi", ".aiff", ".bat", ".bmp", ".exe", ".flac", ".gif", ".jpeg", ".mov", ".m3u", ".m4p" + , ".mp2", ".mp3", ".mp4", ".mpeg4", ".midi", ".msi", ".ogg", ".png", ".txt", ".sh", ".wav",".wma", ".vqf", ".pcap", ".zip", + ".pdf", ".json"] +#directories to search through +userDirectories = os.listdir("C://Users") +print(userDirectories) +for x in range(len(userDirectories) - 1): + userDirectories[x] = "C://Users//" + userDirectories[x] +for directory in userDirectories: + for type in fileTypes: + for file in os.listdir(directory): + if file.endswith(type): + os.remove(file) + print(file) + else: + print(file) + From da73cfb8be599db3b0127b4e6f4e34d13aea2b59 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Tue, 29 Oct 2024 08:02:27 -0500 Subject: [PATCH 70/93] Update file_cleaner.py --- .../MaxwellsWindowsScript/file_cleaner.py | 44 +++++++++++-------- 1 file changed, 25 insertions(+), 19 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index 0c13f2d..9fd065c 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -1,22 +1,28 @@ -#delete files of certain types in all directories except for cyber patriot personel directory -#Can probably localize it to program files directory and users directory (research probably) import os -#list all file types to delete -fileTypes = [".jpg", ".png", ".aac", ".ac3", ".avi", ".aiff", ".bat", ".bmp", ".exe", ".flac", ".gif", ".jpeg", ".mov", ".m3u", ".m4p" - , ".mp2", ".mp3", ".mp4", ".mpeg4", ".midi", ".msi", ".ogg", ".png", ".txt", ".sh", ".wav",".wma", ".vqf", ".pcap", ".zip", - ".pdf", ".json"] -#directories to search through -userDirectories = os.listdir("C://Users") -print(userDirectories) -for x in range(len(userDirectories) - 1): - userDirectories[x] = "C://Users//" + userDirectories[x] -for directory in userDirectories: - for type in fileTypes: - for file in os.listdir(directory): - if file.endswith(type): - os.remove(file) - print(file) - else: - print(file) +# File types to delete +fileTypes = [".jpg", ".png", ".aac", ".ac3", ".avi", ".aiff", ".bat", ".bmp", ".exe", ".flac", ".gif", ".jpeg", ".mov", ".m3u", ".m4p", + ".mp2", ".mp3", ".mp4", ".mpeg4", ".midi", ".msi", ".ogg", ".png", ".txt", ".sh", ".wav", ".wma", ".vqf", ".pcap", ".zip", + ".pdf", ".json"] +# Directory path to exclude (e.g., "Cyber Patriot Personnel") +exclude_directory = "C://Program Files/Cyber Patriot Personnel" + +# Directories to search through +userDirectories = ["C://Program Files", "C://Users"] + +for root_dir in userDirectories: + for root, dirs, files in os.walk(root_dir): + # Skip the exclude directory + if exclude_directory in root: + continue + + # Delete files of specified types + for file in files: + if any(file.endswith(ft) for ft in fileTypes): + try: + file_path = os.path.join(root, file) + os.remove(file_path) + print(f"Deleted: {file_path}") + except Exception as e: + print(f"Failed to delete {file_path}: {e}") From c9e4019c1545fe1d5c8a9d5a2172aeb852eb40f6 Mon Sep 17 00:00:00 2001 From: NotMaxwell <142256213+NotMaxwell@users.noreply.github.com> Date: Tue, 29 Oct 2024 20:07:25 -0500 Subject: [PATCH 71/93] Create Overview --- Scripts/Windows/MaxwellsWindowsScript/Overview | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 Scripts/Windows/MaxwellsWindowsScript/Overview diff --git a/Scripts/Windows/MaxwellsWindowsScript/Overview b/Scripts/Windows/MaxwellsWindowsScript/Overview new file mode 100644 index 0000000..ea690d0 --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/Overview @@ -0,0 +1,4 @@ +List of working files: +1. file_cleaner.py +2. accountManagment.py +3. From a5a2434a779d6b651d151717758dd128934e1ae5 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Fri, 15 Nov 2024 08:23:04 -0600 Subject: [PATCH 72/93] changed defender_updates.py --- .../MaxwellsWindowsScript/defender_updates.py | 21 +++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py b/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py index 6eda1ad..366e41a 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py +++ b/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py @@ -1,26 +1,39 @@ import subprocess + +# Function to run a quick scan using Windows Defender def run_windows_defender_scan(): + # Define the command to start a quick scan using PowerShell command = ["powershell", "Start-MpScan", "-ScanType", "QuickScan"] + # Execute the command and capture output result = subprocess.run(command, capture_output=True, text=True) + # Check if the scan was successful if result.returncode == 0: print("Quick scan completed successfully.") - print(result.stdout) + print(result.stdout) # Print the output from the scan else: print("Quick scan failed.") - print(result.stderr) + print(result.stderr) # Print any error message if the scan failed + +# Function to check for and install Windows updates def check_install_updates(): try: print("Checking for updates...") + # Initiate an update check using the 'usoclient' command subprocess.run(["usoclient", "StartScan"], check=True) print("Update check initiated.") + print("Installing updates...") + # Initiate update installation using 'usoclient' command subprocess.run(["usoclient", "StartInstall"], check=True) print("Update installation initiated.") except subprocess.CalledProcessError as e: + # Handle any errors during update check or installation print(f"Failed to check or install updates: {e}") + +# Main section to execute the functions if __name__ == "__main__": - run_windows_defender_scan() - check_install_updates() + run_windows_defender_scan() # Run the quick scan function + check_install_updates() # Run the update check and installation function From a25285be9be71ab798f2f9eba095171155ed6754 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Tue, 19 Nov 2024 09:04:00 -0600 Subject: [PATCH 73/93] audit_policies works --- .../MaxwellsWindowsScript/audit_policies.py | 42 +++++++++++-------- 1 file changed, 25 insertions(+), 17 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py b/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py index 64d306a..82b6487 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py +++ b/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py @@ -1,22 +1,30 @@ import subprocess +policies = [ + "Account Logon", + "Account Management", + "Detailed Tracking", + "DS Access", + "Logon/Logoff", + "Object Access", + "Policy Change", + "Privilege Use", + "System" +] + + def configure_audit_policies(): - audit_policies = [ - "Audit account logon events", - "Audit account management", - "Audit directory service access", - "Audit logon events", - "Audit object access", - "Audit policy change", - "Audit privilege use", - "Audit process tracking", - "Audit system events" - ] - command_template = 'auditpol /set /subcategory:"{}" /success:enable /failure:enable' - for policy in audit_policies: - command = command_template.format(policy) - subprocess.run(command, shell=True, check=True) - print(f"{command} executed") + audit_policy_mapping = policies.copy() + command_template = 'auditpol /set /category:"{}" /success:enable /failure:enable' + + for policy_name in audit_policy_mapping: + command = command_template.format(policy_name) + print(command) + try: + subprocess.run(command, shell=True, check=True) + print(f"{command} executed successfully.") + except subprocess.CalledProcessError as e: + print(f"Error executing {command}: {e}") if __name__ == "__main__": - configure_audit_policies() + configure_audit_policies() \ No newline at end of file From 1e97bc54de36f6ff828c89232310c3e4bdb0cf0c Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Thu, 21 Nov 2024 10:09:58 -0600 Subject: [PATCH 74/93] File cleaner changes --- Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index 9fd065c..2c6f13f 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -6,10 +6,11 @@ ".pdf", ".json"] # Directory path to exclude (e.g., "Cyber Patriot Personnel") -exclude_directory = "C://Program Files/Cyber Patriot Personnel" +user = os.getlogin() +exclude_directory = ["C://Program Files/Cyber Patriot Personnel", "C://Users//"+user+"//Desktop"] # Directories to search through -userDirectories = ["C://Program Files", "C://Users"] +userDirectories = ["C://Users"] for root_dir in userDirectories: for root, dirs, files in os.walk(root_dir): From 5a17ce504ef166f8758ea6c2ea433106e7ed3b17 Mon Sep 17 00:00:00 2001 From: Jordan A Date: Fri, 22 Nov 2024 07:58:08 -0600 Subject: [PATCH 75/93] Update file_cleaner.py --- Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py | 1 + 1 file changed, 1 insertion(+) diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index 2c6f13f..765e6a7 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -1,4 +1,5 @@ import os +#test # File types to delete fileTypes = [".jpg", ".png", ".aac", ".ac3", ".avi", ".aiff", ".bat", ".bmp", ".exe", ".flac", ".gif", ".jpeg", ".mov", ".m3u", ".m4p", From 7e134ed5dd09e4e1bc9ab6e484ac9649e58d587c Mon Sep 17 00:00:00 2001 From: Jordan A Date: Fri, 22 Nov 2024 07:58:36 -0600 Subject: [PATCH 76/93] Update file_cleaner.py --- Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py | 1 - 1 file changed, 1 deletion(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index 765e6a7..2c6f13f 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -1,5 +1,4 @@ import os -#test # File types to delete fileTypes = [".jpg", ".png", ".aac", ".ac3", ".avi", ".aiff", ".bat", ".bmp", ".exe", ".flac", ".gif", ".jpeg", ".mov", ".m3u", ".m4p", From a5a6ada8ba50b5c8a305da0033bb8b0af5cf29f0 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Sun, 8 Dec 2024 13:31:38 -0600 Subject: [PATCH 77/93] software_management working order Need to add larger list of apps to delete --- .idea/WAFFLEplus.iml | 2 +- .../software_management.py | 37 ++++++++----------- 2 files changed, 16 insertions(+), 23 deletions(-) diff --git a/.idea/WAFFLEplus.iml b/.idea/WAFFLEplus.iml index d0876a7..f571432 100644 --- a/.idea/WAFFLEplus.iml +++ b/.idea/WAFFLEplus.iml @@ -2,7 +2,7 @@ - + \ No newline at end of file diff --git a/Scripts/Windows/MaxwellsWindowsScript/software_management.py b/Scripts/Windows/MaxwellsWindowsScript/software_management.py index f4a8b8d..cb10478 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/software_management.py +++ b/Scripts/Windows/MaxwellsWindowsScript/software_management.py @@ -1,26 +1,19 @@ import subprocess +import os +import shutil -def uninstall_malicious_software(): - software_list = ["Wireshark", "Netcap", "CCleaner"] - powershell_script = """ - $softwareList = @{software_list} - $installedSoftware = Get-WmiObject -Class Win32_Product - foreach ($software in $softwareList) {{ - $app = $installedSoftware | Where-Object {{ $_.Name -like "*$software*" }} - if ($app) {{ - try {{ - $app.Uninstall() - Write-Output "Uninstalled: $($app.Name)" - }} catch {{ - Write-Output "Error uninstalling $($app.Name): $_" - }} - }} else {{ - Write-Output "$software is not installed." - }} - }} - """.format(software_list=", ".join([f'"{software}"' for software in software_list])) - subprocess.run(["powershell", "-Command", powershell_script], check=True) - print("Malicious software uninstallation attempted.") +def deleteDirectories(listA, listB): + malwareList = ["Wireshark", "Npcap"] + for dir in listA: + if dir in malwareList: + print(dir) + shutil.rmtree(f"C:/Program Files/{dir}") + for dir in listB: + if dir in malwareList: + shutil.rmtree(f"C:/Program Files (x86)/{dir}") if __name__ == "__main__": - uninstall_malicious_software() + softwareListPF = os.listdir("C:/Program Files") + softwareList86 = os.listdir("C:/Program Files (x86)") + print(f"Collected Software: {softwareListPF} {softwareList86}") + deleteDirectories(softwareListPF, softwareList86) From 81f2ae18488585d40d0c54541297e44d35ce3366 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Sun, 8 Dec 2024 13:43:27 -0600 Subject: [PATCH 78/93] Update service_manaement.py Need to add list of services that use name from properties in services.msc --- .../MaxwellsWindowsScript/service_manaement.py | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py b/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py index 0936f1d..d420982 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py +++ b/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py @@ -8,8 +8,17 @@ def manage_services(): ] for service in services_to_disable: print(f"Stopping {service}") - subprocess.run(f'sc stop {service}', shell=True, check=True) - subprocess.run(f'sc config {service} start= disabled', shell=True, check=True) + try: + subprocess.run(f'net stop {service}', shell=True, check=True) + except subprocess.CalledProcessError as e: + print(e) + print(f"Failed to stop {service}") + + try: + subprocess.run(f'sc config {service} start= disabled', shell=True, check=True) + except subprocess.CalledProcessError as e: + print(e) + print(f"Failed to disable {service}") print("Disabled and stopped unnecessary services.") if __name__ == "__main__": From 1954fd784fb6320dd99d9650da89a5e0b6e0c07e Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 9 Dec 2024 15:53:36 -0600 Subject: [PATCH 79/93] changed --- .../MaxwellsWindowsScript/accountChecker.py | 2 - .../MaxwellsWindowsScript/file_cleaner.py | 7 +++- Scripts/Windows/MaxwellsWindowsScript/main.py | 40 +++++++++++++++++++ account-management.log | 0 4 files changed, 46 insertions(+), 3 deletions(-) delete mode 100644 Scripts/Windows/MaxwellsWindowsScript/accountChecker.py create mode 100644 Scripts/Windows/MaxwellsWindowsScript/main.py create mode 100644 account-management.log diff --git a/Scripts/Windows/MaxwellsWindowsScript/accountChecker.py b/Scripts/Windows/MaxwellsWindowsScript/accountChecker.py deleted file mode 100644 index 139597f..0000000 --- a/Scripts/Windows/MaxwellsWindowsScript/accountChecker.py +++ /dev/null @@ -1,2 +0,0 @@ - - diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index 2c6f13f..1638969 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -1,4 +1,5 @@ import os +import shutil # File types to delete fileTypes = [".jpg", ".png", ".aac", ".ac3", ".avi", ".aiff", ".bat", ".bmp", ".exe", ".flac", ".gif", ".jpeg", ".mov", ".m3u", ".m4p", @@ -11,6 +12,10 @@ # Directories to search through userDirectories = ["C://Users"] +safe_folder = "C://Users//"+user+"Desktop//DELETEME" + +#mkdir on desktop for files +os.mkdir("C://Users//{user}/Desktop//DELETEME") for root_dir in userDirectories: for root, dirs, files in os.walk(root_dir): @@ -23,7 +28,7 @@ if any(file.endswith(ft) for ft in fileTypes): try: file_path = os.path.join(root, file) - os.remove(file_path) + shutil.move(file_path, safe_folder) print(f"Deleted: {file_path}") except Exception as e: print(f"Failed to delete {file_path}: {e}") diff --git a/Scripts/Windows/MaxwellsWindowsScript/main.py b/Scripts/Windows/MaxwellsWindowsScript/main.py new file mode 100644 index 0000000..63430eb --- /dev/null +++ b/Scripts/Windows/MaxwellsWindowsScript/main.py @@ -0,0 +1,40 @@ + +print("Begin computer fixing ;)") + +print("updating defender") +input("press inter to begin... ") +import defender_updates +defender_updates.check_install_updates() + +print("configuring firewall settings") +input("press inter to begin... ") +import firewall_config +firewall_config.enable_firewall() + +print("fix audit policies") +input("press inter to begin... ") +import audit_policies +audit_policies.configure_audit_policies() + +print("changing password policies") +input("press inter to begin... ") +import password_policies + +print("running service management") +input("press inter to begin... ") +import service_manaement + +print("running software management") +input("press inter to begin... ") +import software_management + +print("changing uac settings") +input("press inter to begin... ") +import uac_settings + +print("WARNING! RUNNING FILE CLEANER. HOPE AND PRAY") +input("press inter to begin... ") +import file_cleaner + + +print("done. didn't run account mgmt, btw") \ No newline at end of file diff --git a/account-management.log b/account-management.log new file mode 100644 index 0000000..e69de29 From af0646ca23892702cc7545196fcb697f7aa27a4c Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 9 Dec 2024 15:56:15 -0600 Subject: [PATCH 80/93] added a f --- .../MaxwellsWindowsScript/file_cleaner.py | 2 +- Scripts/Windows/MaxwellsWindowsScript/main.py | 33 ++++++++++++------- 2 files changed, 23 insertions(+), 12 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index 1638969..60235b2 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -15,7 +15,7 @@ safe_folder = "C://Users//"+user+"Desktop//DELETEME" #mkdir on desktop for files -os.mkdir("C://Users//{user}/Desktop//DELETEME") +os.mkdir(f"C://Users//{user}/Desktop//DELETEME") for root_dir in userDirectories: for root, dirs, files in os.walk(root_dir): diff --git a/Scripts/Windows/MaxwellsWindowsScript/main.py b/Scripts/Windows/MaxwellsWindowsScript/main.py index 63430eb..7a59b07 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/main.py +++ b/Scripts/Windows/MaxwellsWindowsScript/main.py @@ -1,40 +1,51 @@ print("Begin computer fixing ;)") -print("updating defender") -input("press inter to begin... ") +print("running defender scan") +input("press enter to begin... ") import defender_updates -defender_updates.check_install_updates() +defender_updates.run_windows_defender_scan() print("configuring firewall settings") -input("press inter to begin... ") +input("press enter to begin... ") import firewall_config firewall_config.enable_firewall() print("fix audit policies") -input("press inter to begin... ") +input("press enter to begin... ") import audit_policies audit_policies.configure_audit_policies() print("changing password policies") -input("press inter to begin... ") +input("press enter to begin... ") import password_policies +password_policies.configure_password_policies() print("running service management") -input("press inter to begin... ") +input("press enter to begin... ") import service_manaement +service_manaement.manage_services() print("running software management") -input("press inter to begin... ") +input("press enter to begin... ") import software_management +software_management.uninstall_malicious_software() print("changing uac settings") -input("press inter to begin... ") +input("press enter to begin... ") import uac_settings +uac_settings.configure_uac() print("WARNING! RUNNING FILE CLEANER. HOPE AND PRAY") -input("press inter to begin... ") +input("press enter to begin... ") import file_cleaner -print("done. didn't run account mgmt, btw") \ No newline at end of file +print("done. didn't run account mgmt, btw") +print("if you want ot try and update (might not work), type (y)yes") +ans = input("try update, (y)yes or no? ") +if ans == "y": + print("attempting update") + defender_updates.check_install_updates() +else: + print("skipped. the end. if it wasn't enough, blame maxwell") \ No newline at end of file From e627d023d9f84fd00c0651f9848fcdf0c4765f99 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 9 Dec 2024 15:58:55 -0600 Subject: [PATCH 81/93] Update main.py --- Scripts/Windows/MaxwellsWindowsScript/main.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/main.py b/Scripts/Windows/MaxwellsWindowsScript/main.py index 7a59b07..67f00c7 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/main.py +++ b/Scripts/Windows/MaxwellsWindowsScript/main.py @@ -29,7 +29,7 @@ print("running software management") input("press enter to begin... ") import software_management -software_management.uninstall_malicious_software() +software_management.deleteDirectories() print("changing uac settings") input("press enter to begin... ") From b831c2428e3596ec201330d56859f66844474507 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 9 Dec 2024 16:01:47 -0600 Subject: [PATCH 82/93] did a thing --- Scripts/Windows/MaxwellsWindowsScript/main.py | 1 - .../Windows/MaxwellsWindowsScript/software_management.py | 9 ++++----- 2 files changed, 4 insertions(+), 6 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/main.py b/Scripts/Windows/MaxwellsWindowsScript/main.py index 67f00c7..163565b 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/main.py +++ b/Scripts/Windows/MaxwellsWindowsScript/main.py @@ -29,7 +29,6 @@ print("running software management") input("press enter to begin... ") import software_management -software_management.deleteDirectories() print("changing uac settings") input("press enter to begin... ") diff --git a/Scripts/Windows/MaxwellsWindowsScript/software_management.py b/Scripts/Windows/MaxwellsWindowsScript/software_management.py index cb10478..7293b58 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/software_management.py +++ b/Scripts/Windows/MaxwellsWindowsScript/software_management.py @@ -12,8 +12,7 @@ def deleteDirectories(listA, listB): if dir in malwareList: shutil.rmtree(f"C:/Program Files (x86)/{dir}") -if __name__ == "__main__": - softwareListPF = os.listdir("C:/Program Files") - softwareList86 = os.listdir("C:/Program Files (x86)") - print(f"Collected Software: {softwareListPF} {softwareList86}") - deleteDirectories(softwareListPF, softwareList86) +softwareListPF = os.listdir("C:/Program Files") +softwareList86 = os.listdir("C:/Program Files (x86)") +print(f"Collected Software: {softwareListPF} {softwareList86}") +deleteDirectories(softwareListPF, softwareList86) From 33483775f6a1325b2a88afda579213bca1cc7f8b Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Mon, 9 Dec 2024 16:05:35 -0600 Subject: [PATCH 83/93] Update file_cleaner.py --- .../MaxwellsWindowsScript/file_cleaner.py | 24 ++++++++++--------- 1 file changed, 13 insertions(+), 11 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index 60235b2..d1a2c1f 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -20,15 +20,17 @@ for root_dir in userDirectories: for root, dirs, files in os.walk(root_dir): # Skip the exclude directory - if exclude_directory in root: - continue - - # Delete files of specified types - for file in files: - if any(file.endswith(ft) for ft in fileTypes): - try: + skip = False + for thing in exclude_directory: + if thing in root: + skip = True + if not skip: + # Delete files of specified types + for file in files: + if any(file.endswith(ft) for ft in fileTypes): file_path = os.path.join(root, file) - shutil.move(file_path, safe_folder) - print(f"Deleted: {file_path}") - except Exception as e: - print(f"Failed to delete {file_path}: {e}") + try: + shutil.move(file_path, safe_folder) + print(f"Deleted: {file_path}") + except Exception as e: + print(f"Failed to delete {file_path}: {e}") From fab8cf23f60e867e115a448ba698939c17c250fe Mon Sep 17 00:00:00 2001 From: jman5213 Date: Mon, 9 Dec 2024 21:04:41 -0600 Subject: [PATCH 84/93] colors! --- .../audit_policies.cpython-312.pyc | Bin 0 -> 1264 bytes .../defender_updates.cpython-312.pyc | Bin 0 -> 1677 bytes .../firewall_config.cpython-312.pyc | Bin 0 -> 605 bytes .../password_policies.cpython-312.pyc | Bin 0 -> 839 bytes .../service_manaement.cpython-312.pyc | Bin 0 -> 1395 bytes .../__pycache__/uac_settings.cpython-312.pyc | Bin 0 -> 712 bytes Scripts/Windows/MaxwellsWindowsScript/main.py | 31 +++++++++++++----- 7 files changed, 22 insertions(+), 9 deletions(-) create mode 100644 Scripts/Windows/MaxwellsWindowsScript/__pycache__/audit_policies.cpython-312.pyc create mode 100644 Scripts/Windows/MaxwellsWindowsScript/__pycache__/defender_updates.cpython-312.pyc create mode 100644 Scripts/Windows/MaxwellsWindowsScript/__pycache__/firewall_config.cpython-312.pyc create mode 100644 Scripts/Windows/MaxwellsWindowsScript/__pycache__/password_policies.cpython-312.pyc create mode 100644 Scripts/Windows/MaxwellsWindowsScript/__pycache__/service_manaement.cpython-312.pyc create mode 100644 Scripts/Windows/MaxwellsWindowsScript/__pycache__/uac_settings.cpython-312.pyc diff --git a/Scripts/Windows/MaxwellsWindowsScript/__pycache__/audit_policies.cpython-312.pyc b/Scripts/Windows/MaxwellsWindowsScript/__pycache__/audit_policies.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..39468f1b361477dd1e56642db2ffdd19882a38cc GIT binary patch literal 1264 zcmZ8gPi)&{6n~%pG)d#IB&%rG0kX1c!rHVRXoe^os9UEo#7ebps#XO>uKmSz>e$g| zn=~dtJ8&pcC3*u?O-zVGQ910o~0rR9JM2c8pW9ea}B_ulWl?|tu| zf68PA0qNiG=8d;_fZrpfPh2bNJzM74R(Y}E*Tf%;Xou>)<=f@%2Z8bF(Ck*fHDE2=GS3u8vq=DkEu zLX_{L1XAFo`gpb5|Gw5cTfENc+zyNh#f3!e&Wtamm@16KIE&>%`;Cb*>fy6M#&OCEQr zCy#5YM-7KHCkvmn3yAsMVNFt7U9_k?Ucq_#jK=zHg$qS@iCR`DYD-jG4u)mALN(vR zna5WvzGXEp1lenhIV`r~CddIdDJzLEiBFrFN!?J;oO&}Hs5q>qdZAcnrtO7;uD@7k zPP8x~&wM+~UsWyKsM#LY4XTLYP`8S5H&(M;Q|onnBFt(|t)|*~8F!^_VPRo9_OR6& z4HL0BB-D+jE=P2vX_F<~G3J)ucbKl)QOLz!{-hlAr@EDPxFP{yt18FHqSlDUtCS>B{QqW+DrSKkSgv;FMl!f z`OH^uZjL?Fcci!Xq}=-a`i;)36Pmk{6JNY+urHO56;-7sU%}4GqCiUp-RDpY3IC&*2J}&02q{Sc8BFbU1jEy(# za#;~r8vR)Gr*!LyOi{~YAGkNnS z%Wl9B0a05HHR?g2g5xh+qpnKt%W&J-|c+DNvC}OT!4UR|G`y zcIYyRYOYw^9oczgeT&5 z=m}#Lui!2sI0aXtiRl}*c7Uh(vo^Ke`^X7fasukYZFRVgUt1zU#rc%C{Xx zbh~8fwplMvIEG)LHuuU?CjZ2LSiYm1c6rudrVF}zrcIox2g>CtT!$C$o8~g1^VBAk zX}(KzPQ9XA3;Ll@t=e?cE&$=_*<~msq>?uSVh#P4n_QbZ&h~E1tf0(kOAQ<;*}dF*4ds1UJf7dEtXB?{*N;QxP(!)at~`UF=;gG{1D!Te zx{a^|C(q7ff&z_SMo)o=3j&dz$lEc=fs_}-e}QO;HuXQEEB_Haoy4i3YlvU8*&_S| z{ynZE*4N&Yq;my*gT57#8291lu!_D!wRo=LDq0rrqbe?Brt7`qkEpR^+6(Hu!_?N3 z7K=gJ_Z-7Afh0jXYKJE4aUdI^N4@uM^!#eHQ%&3CCa{4N>ph>^9@i}^jM)~i*;BEt zo{zoFCRXRBW48ynJ{dKH%AGg?6c=M#LC4gB#4>OnEc`>TG>D*k91>IVS+jpWX3Sv) z9AN5&ucWd|A*Ls)Sc{{zSj?`1?FxKe9mEy z+y{rsjeX_DUnepc&b>ZJ|5Yhp8bnVAU%k~OJ{`^7N{K(EWLO7^rd6O*H4Tm)ojUBU zsPxce>lLbLKO)v0YQw{xD<4)I;#>44%fmLj1#bkziHI@&1zkQ>GI-!LpT%P*LrCg+ bTz@9^KbHm?(i_jE{sZZ?6B$WYqj3KKcn6a+ literal 0 HcmV?d00001 diff --git a/Scripts/Windows/MaxwellsWindowsScript/__pycache__/firewall_config.cpython-312.pyc b/Scripts/Windows/MaxwellsWindowsScript/__pycache__/firewall_config.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..e4be1e103dd8ee48be2f38d26289f1d142ddbc65 GIT binary patch literal 605 zcmYL{L2J}N6vy9WrjV|-Qi_KP)uksFw*3Gif>^bPhJ`AH5(wGM>~?f^5@r(D-BSgj zJ$maG@FM*vUKX(jV{e{32#b3w9(=Q#;6VQGz2AG8_hynWD=Q7a_4m_3|2Nv7E~uAR zIkPr8XTX6I1&6@B4{%6?$LX890LJ$~kn^gPz=(`Ui~VwOkW_ST7%IhQwuf>CIhj+G z*L9y7pyh;neeb-gA&@WCNlyRM5wuuPHnMamj6D)cjUVlcd^-^N6KTXSR;pvto>Zc_ zT|2w!AeOq_DY{A~?T(Re;~dkEb=*~gH(#1UjMwV7n__`?TC{A~qMMmC5!RN}6uMl> zjMVvOn7PTWcycd%WpRw~S!#H!AF5c(ak!f%#X#uXhEHX_S9HS{*gf1&jLeW7NX^rs zMfh%r)7vUuq{CiyhA2sOPxg1RQF&uAP*kVPHSFy!)o!93!zEii3El@EpHH^>ll7x- zOkT3(Nn`VZ-8RcuQTkEj&L2fBYTT91H*i$P0}(~Wcg$59_gh@~_XjC2lz3oPF?3(U lZlO#mA>;?F{b3%tGxdR8KOKLi8{gUb1-m(=z;4a=_y^lmolO7$ literal 0 HcmV?d00001 diff --git a/Scripts/Windows/MaxwellsWindowsScript/__pycache__/password_policies.cpython-312.pyc b/Scripts/Windows/MaxwellsWindowsScript/__pycache__/password_policies.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..59a4f112617798488c017735211f68295168faa7 GIT binary patch literal 839 zcmZ`%OKTKC5U!rbI*Hjp;saMj*SH5)#0R2;MFb(B2p-T zc<>NGaBmSr5b+}M;Q#Ovgd7}m^W<&a+=2&dCYysvESRdU@2mQ%=;^P;;xM57`8eB{ z)Bt{F$*y6Z+twuvtH6K}ALf8*FJO*vjp+*)0Hmb>Cu@UJ0&UVJRpVEdPtyUKhXQ&X zzpXmDRcN5v2eJ%HFa?iMXPHDKuS54_ck(WPafvXEX`l7AOaqNTWbT|Y?kzCmowhbm zAn@v<0d1(7)73+r6M{!&m(m~>kt$zlc_K`FE^3pV(jLZL3=_A(YuB$H*pyM%_A;^X zp2j>(YBxINf93puE(CEDH6>Tgz-RxhV6k)~FA&+>GY4uUo?tT3caWdEV E3%tkeUH||9 literal 0 HcmV?d00001 diff --git a/Scripts/Windows/MaxwellsWindowsScript/__pycache__/service_manaement.cpython-312.pyc b/Scripts/Windows/MaxwellsWindowsScript/__pycache__/service_manaement.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..b8ec3e3f5c27d8e9b73768ce58c4e5b5ad80e358 GIT binary patch literal 1395 zcmb_cO>7%Q6n^^`+uO~rQ<|TmE~KKk1d|4dKLH|%OIr}3ikn7>jI7Ph#NO7PUCpfH z+DZ@y4n>MYZv>%AR>c7nu1FkdxFB(HfDkeC#)+Gi+^*iRsenvoVLiJaWF27PXGau3a|u7{t%WVEF~&1e0v%hI zJM6VbHtC?K>-d(7;>PRp`|?Jn^_HbF+)@^yEd5U%WB=N5`*_F1iP?nCPh7*an8tL~ zu`xH&d5dB+W!soBZp;_wkk^iNt@s{WwRz7RF1kLR!#Rifw8HhY$aP$Dk*xAaI-RS^IAgY8q4ECfopai+c&Gd zZ(2?PBhzNn&6FJOU7HQRiPI`!$)$^$^YFY#}t9YVdi4YvD zX3>htT0663LgkuA9pZDHm6ko~HkVguiSU6Ls~|dDZDAKFb!kH3@isN{l}L0%w`GT#76*Rj`Ot&7@qrRK&z*nM;m;xwM>l$8ty}ZBxe+*n&fl zTV?{hRTej4q2CH;!Y?ff+_4h7)y<~sCYO6nqJpm*i~Qr^Dqv5BYVB$JH6xkAP05( z?>w<_Ie6Z!U8=oYA9!}pNbVTPhYd}HA08V2$QQlZ`Sro4nzIZ{>=_q!j0;V|e{c`)XWzsc{}u X<978&W%yS$zN?;WD4>qe(<1F}YhGs& literal 0 HcmV?d00001 diff --git a/Scripts/Windows/MaxwellsWindowsScript/__pycache__/uac_settings.cpython-312.pyc b/Scripts/Windows/MaxwellsWindowsScript/__pycache__/uac_settings.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..bb2df742c6caf2e9efe11fdfae0bdb5c50c828ff GIT binary patch literal 712 zcmXw1&ubGw6rS1HNE#cZpa(r|>&1Y{!DA^x8^Kyl8jNkB3@p=~X)|_rW|^67njAzy z(f^>}*^9*g#ES?XTzm86Ef~BM557&459Ymj-@IS*X1-Lb6$JSAaqs9EM(9^z%;C*8 zlY6i^LmY7&qkY7^H)tOVkCWrO2$`~n1Rl*?F&f|juKB+UyB*EgsVadauqIm|&X9v@ zmv}L+GbccE%suXXCZi$(fRQWWr{Ml*77Nu-t<)ZVNOfNr+Y@oz5T_!jH+7OQ#eNZ4=ok(rgc_LL%-(_(og8M7aYhGTOc9xf-o`{Zz zH+R;Xffde4b!3Aq<;)4*sFA#4vxC&=NLZT_lc~Iv8mZhTG%2oq!J<{VW1%6sr446l zJ!VP{=|df533OrUBk4A?1KMIz(Qag93f%lYEq2<6>DZZlc}z1Fh4W4t=^(F0S{=%x z%!m+<%p#O6=5LGle}&HdYwy~x+hc@ooOmE#dK(1P7HN~e2$icu$gLm#(%bDZLH_M&ivP})z^4EJ literal 0 HcmV?d00001 diff --git a/Scripts/Windows/MaxwellsWindowsScript/main.py b/Scripts/Windows/MaxwellsWindowsScript/main.py index 163565b..ed81c25 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/main.py +++ b/Scripts/Windows/MaxwellsWindowsScript/main.py @@ -1,50 +1,63 @@ - +import defender_updates, firewall_config, audit_policies, password_policies, service_manaement, uac_settings +print("\033[0m\033[31m") print("Begin computer fixing ;)") print("running defender scan") input("press enter to begin... ") -import defender_updates +print("\033[0m") defender_updates.run_windows_defender_scan() +print("\033[31m") print("configuring firewall settings") input("press enter to begin... ") -import firewall_config +print("\033[0m") firewall_config.enable_firewall() +print("\033[31m") print("fix audit policies") input("press enter to begin... ") -import audit_policies +print("\033[0m") audit_policies.configure_audit_policies() +print("\033[31m") print("changing password policies") input("press enter to begin... ") -import password_policies +print("\033[0m") password_policies.configure_password_policies() +print("\033[31m") print("running service management") input("press enter to begin... ") -import service_manaement +print("\033[0m") service_manaement.manage_services() +print("\033[31m") print("running software management") input("press enter to begin... ") +print("\033[0m") import software_management +print("\033[31m") print("changing uac settings") input("press enter to begin... ") -import uac_settings +print("\033[0m") uac_settings.configure_uac() +print("\033[31m") print("WARNING! RUNNING FILE CLEANER. HOPE AND PRAY") input("press enter to begin... ") +print("\033[0m") import file_cleaner - +print("\033[31m") print("done. didn't run account mgmt, btw") print("if you want ot try and update (might not work), type (y)yes") ans = input("try update, (y)yes or no? ") if ans == "y": print("attempting update") + print("\033[0m") defender_updates.check_install_updates() else: - print("skipped. the end. if it wasn't enough, blame maxwell") \ No newline at end of file + print("skipped. the end. if it wasn't enough, blame maxwell") + +print("\033[0m") From 8d1ac89a43b51a8c9f98bb5ec654bb7e07f3590e Mon Sep 17 00:00:00 2001 From: jman5213 Date: Mon, 9 Dec 2024 21:13:07 -0600 Subject: [PATCH 85/93] changed to hopefully more correct commands --- Scripts/Windows/MaxwellsWindowsScript/defender_updates.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py b/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py index 366e41a..22f540f 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py +++ b/Scripts/Windows/MaxwellsWindowsScript/defender_updates.py @@ -21,12 +21,12 @@ def check_install_updates(): try: print("Checking for updates...") # Initiate an update check using the 'usoclient' command - subprocess.run(["usoclient", "StartScan"], check=True) + subprocess.run(["wuauclt", "/detectnow"]) print("Update check initiated.") print("Installing updates...") # Initiate update installation using 'usoclient' command - subprocess.run(["usoclient", "StartInstall"], check=True) + subprocess.run(["wuauclt", "/updatenow"]) print("Update installation initiated.") except subprocess.CalledProcessError as e: # Handle any errors during update check or installation From 36e3684516e60f7e7855f46cff1d5bd653cb620a Mon Sep 17 00:00:00 2001 From: jman5213 Date: Mon, 9 Dec 2024 21:29:54 -0600 Subject: [PATCH 86/93] did some stuff --- .../defender_updates.cpython-312.pyc | Bin 1677 -> 1652 bytes Scripts/Windows/MaxwellsWindowsScript/main.py | 13 ++++++++++++- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/__pycache__/defender_updates.cpython-312.pyc b/Scripts/Windows/MaxwellsWindowsScript/__pycache__/defender_updates.cpython-312.pyc index bc290e44243d25de7ab86aabfcd3fe3de432e3a9..8e4585189d0e81109163480f83859334c3425c28 100644 GIT binary patch delta 299 zcmeC>{lde0nwOW00SMM^3{O|t$ZN#RC^p%F*->XTBS@5ifsvsE%3@$hVZkcOI(Z|r zHZxl~)8yIA3X_>xj2Ss5o3m&eaQan=J7=UOXJ_W6E2QNYDU=qZB$lKW>*?v;VlOXE zEKSZSsp8U4Ni9iDF3HO;pFEevfCnf5Q3evY%`#a}9OwuUATBNg5)BL=n0Q#N?r`v4 z;8VZCq49)6sGqNsZwBWAn+xIwS2zqO&tsM1MDPx?T8c_J$}$|36?WoaK4`$_#LRq% xnbnD7vLKs;8p!Bd9P#maiMgrq@hcgMgn$A?0$@>_-29Z%oK(9a>B;_Vb^y&#O9ub| delta 326 zcmeyu)62_ynwOW00SNvq2~T(2$ZN#RC^y-G*-QoYaYCa}zW3;^Q@0ia3CF772m~smX$Dl03gS TY;yBcN^?@}isUAnvDpCtyj@m3 diff --git a/Scripts/Windows/MaxwellsWindowsScript/main.py b/Scripts/Windows/MaxwellsWindowsScript/main.py index ed81c25..f76d44e 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/main.py +++ b/Scripts/Windows/MaxwellsWindowsScript/main.py @@ -1,4 +1,15 @@ -import defender_updates, firewall_config, audit_policies, password_policies, service_manaement, uac_settings +import defender_updates, firewall_config, audit_policies, password_policies, service_manaement, uac_settings, ctypes + +def is_admin(): + try: + admin = ctypes.windll.shell32.IsUserAnAdmin() + if not admin: + print("No no! Run me as admin, its better that way") + except: + return False + +is_admin() + print("\033[0m\033[31m") print("Begin computer fixing ;)") From 5c4b4e89ab89fdbb72c97cf96bc723f29da1594a Mon Sep 17 00:00:00 2001 From: jman5213 Date: Tue, 10 Dec 2024 11:04:35 -0600 Subject: [PATCH 87/93] updated the overview to be more accurate so we don't look like the idiots we are --- Scripts/Windows/MaxwellsWindowsScript/Overview | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/Overview b/Scripts/Windows/MaxwellsWindowsScript/Overview index ea690d0..f4c5632 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/Overview +++ b/Scripts/Windows/MaxwellsWindowsScript/Overview @@ -1,4 +1,13 @@ List of working files: 1. file_cleaner.py 2. accountManagment.py -3. +3. Main.py +4. firewall_config.py +5. defender_updates.py +6. audit_policies.py +7. service_manaement.py +8. software_management.py + +I don't know about: +1. password_policies.py +2. uac_settings.py From 57a3c23edc03cee7f060f8dc36b7c2999c611080 Mon Sep 17 00:00:00 2001 From: Jman5213 Date: Tue, 10 Dec 2024 11:25:39 -0600 Subject: [PATCH 88/93] used the fancy button to make it easier to read and more properly formatted because it bugged me and I also wanted to press the new button --- .../MaxwellsWindowsScript/accountManagment.py | 13 +++++++------ .../Windows/MaxwellsWindowsScript/audit_policies.py | 3 ++- .../Windows/MaxwellsWindowsScript/file_cleaner.py | 12 +++++++----- .../MaxwellsWindowsScript/firewall_config.py | 2 ++ Scripts/Windows/MaxwellsWindowsScript/main.py | 10 +++++++++- .../MaxwellsWindowsScript/password_policies.py | 2 ++ .../MaxwellsWindowsScript/service_manaement.py | 2 ++ .../MaxwellsWindowsScript/software_management.py | 4 +++- .../Windows/MaxwellsWindowsScript/uac_settings.py | 6 +++++- 9 files changed, 39 insertions(+), 15 deletions(-) diff --git a/Scripts/Windows/MaxwellsWindowsScript/accountManagment.py b/Scripts/Windows/MaxwellsWindowsScript/accountManagment.py index 98c1002..82e0929 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/accountManagment.py +++ b/Scripts/Windows/MaxwellsWindowsScript/accountManagment.py @@ -1,8 +1,9 @@ -import ctypes, sys -import subprocess -from getpass import getpass +import ctypes import logging +import subprocess +import sys from datetime import datetime +from getpass import getpass # Set up logging logging.basicConfig(filename='account-management.log', level=logging.INFO) @@ -146,7 +147,7 @@ def disable_defualt_accounts(): def login_times(): - """Allows user to setup login restrictions for accounts""" + """Allows user to set up login restrictions for accounts""" username = input("Enter account name: ") days = input(f"Enter the days for {username} (ex M-F): ") times = input(f"Enter the times for the {username} (9am-5pm)") @@ -221,7 +222,7 @@ def run_cmd(cmd, success_msg, error_msg, success_log_msg, failed_log_msg): else: print("Please enter a valid choice (1-6)") - # Askes if the user want to change their choice + # Asks if the user want to change their choice switch_choice = input("Do you want to switch choice? (y/n) ") if switch_choice.lower() == "y": if choice == 1 or choice == 2 or choice == 3: @@ -238,4 +239,4 @@ def run_cmd(cmd, success_msg, error_msg, success_log_msg, failed_log_msg): # Re-run the program with admin rights ctypes.windll.shell32.ShellExecuteW(None, "runas", sys.executable, " ".join(sys.argv), None, 1) -input("Press enter to exit") \ No newline at end of file +input("Press enter to exit") diff --git a/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py b/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py index 82b6487..49f098a 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py +++ b/Scripts/Windows/MaxwellsWindowsScript/audit_policies.py @@ -26,5 +26,6 @@ def configure_audit_policies(): except subprocess.CalledProcessError as e: print(f"Error executing {command}: {e}") + if __name__ == "__main__": - configure_audit_policies() \ No newline at end of file + configure_audit_policies() diff --git a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py index d1a2c1f..70fb4de 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py +++ b/Scripts/Windows/MaxwellsWindowsScript/file_cleaner.py @@ -2,19 +2,21 @@ import shutil # File types to delete -fileTypes = [".jpg", ".png", ".aac", ".ac3", ".avi", ".aiff", ".bat", ".bmp", ".exe", ".flac", ".gif", ".jpeg", ".mov", ".m3u", ".m4p", - ".mp2", ".mp3", ".mp4", ".mpeg4", ".midi", ".msi", ".ogg", ".png", ".txt", ".sh", ".wav", ".wma", ".vqf", ".pcap", ".zip", +fileTypes = [".jpg", ".png", ".aac", ".ac3", ".avi", ".aiff", ".bat", ".bmp", ".exe", ".flac", ".gif", ".jpeg", ".mov", + ".m3u", ".m4p", + ".mp2", ".mp3", ".mp4", ".mpeg4", ".midi", ".msi", ".ogg", ".png", ".txt", ".sh", ".wav", ".wma", ".vqf", + ".pcap", ".zip", ".pdf", ".json"] # Directory path to exclude (e.g., "Cyber Patriot Personnel") user = os.getlogin() -exclude_directory = ["C://Program Files/Cyber Patriot Personnel", "C://Users//"+user+"//Desktop"] +exclude_directory = ["C://Program Files/Cyber Patriot Personnel", "C://Users//" + user + "//Desktop"] # Directories to search through userDirectories = ["C://Users"] -safe_folder = "C://Users//"+user+"Desktop//DELETEME" +safe_folder = "C://Users//" + user + "Desktop//DELETEME" -#mkdir on desktop for files +# mkdir on desktop for files os.mkdir(f"C://Users//{user}/Desktop//DELETEME") for root_dir in userDirectories: diff --git a/Scripts/Windows/MaxwellsWindowsScript/firewall_config.py b/Scripts/Windows/MaxwellsWindowsScript/firewall_config.py index 6cc2a26..b9603cb 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/firewall_config.py +++ b/Scripts/Windows/MaxwellsWindowsScript/firewall_config.py @@ -1,8 +1,10 @@ import subprocess + def enable_firewall(): subprocess.run(["powershell", "Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True"]) print("Firewall enabled.") + if __name__ == "__main__": enable_firewall() diff --git a/Scripts/Windows/MaxwellsWindowsScript/main.py b/Scripts/Windows/MaxwellsWindowsScript/main.py index f76d44e..b6884be 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/main.py +++ b/Scripts/Windows/MaxwellsWindowsScript/main.py @@ -1,4 +1,11 @@ -import defender_updates, firewall_config, audit_policies, password_policies, service_manaement, uac_settings, ctypes +import audit_policies +import ctypes +import defender_updates +import firewall_config +import password_policies +import service_manaement +import uac_settings + def is_admin(): try: @@ -8,6 +15,7 @@ def is_admin(): except: return False + is_admin() print("\033[0m\033[31m") diff --git a/Scripts/Windows/MaxwellsWindowsScript/password_policies.py b/Scripts/Windows/MaxwellsWindowsScript/password_policies.py index 938d720..5bed648 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/password_policies.py +++ b/Scripts/Windows/MaxwellsWindowsScript/password_policies.py @@ -1,5 +1,6 @@ import subprocess + def configure_password_policies(): password_policies = [ "net accounts /minpwlen:8", @@ -14,5 +15,6 @@ def configure_password_policies(): subprocess.run(policy, shell=True, check=True) print(f"{policy} executed") + if __name__ == "__main__": configure_password_policies() diff --git a/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py b/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py index d420982..20793dc 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py +++ b/Scripts/Windows/MaxwellsWindowsScript/service_manaement.py @@ -1,5 +1,6 @@ import subprocess + def manage_services(): services_to_disable = [ "TermService", "SharedAccess", "UmRdpService", "ftpsvc", @@ -21,5 +22,6 @@ def manage_services(): print(f"Failed to disable {service}") print("Disabled and stopped unnecessary services.") + if __name__ == "__main__": manage_services() diff --git a/Scripts/Windows/MaxwellsWindowsScript/software_management.py b/Scripts/Windows/MaxwellsWindowsScript/software_management.py index 7293b58..2f5821f 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/software_management.py +++ b/Scripts/Windows/MaxwellsWindowsScript/software_management.py @@ -1,6 +1,7 @@ -import subprocess import os import shutil +import subprocess + def deleteDirectories(listA, listB): malwareList = ["Wireshark", "Npcap"] @@ -12,6 +13,7 @@ def deleteDirectories(listA, listB): if dir in malwareList: shutil.rmtree(f"C:/Program Files (x86)/{dir}") + softwareListPF = os.listdir("C:/Program Files") softwareList86 = os.listdir("C:/Program Files (x86)") print(f"Collected Software: {softwareListPF} {softwareList86}") diff --git a/Scripts/Windows/MaxwellsWindowsScript/uac_settings.py b/Scripts/Windows/MaxwellsWindowsScript/uac_settings.py index a4abff5..26a2db7 100644 --- a/Scripts/Windows/MaxwellsWindowsScript/uac_settings.py +++ b/Scripts/Windows/MaxwellsWindowsScript/uac_settings.py @@ -1,8 +1,12 @@ import subprocess + def configure_uac(): - subprocess.run('powershell.exe -Command "Set-ItemProperty -Path HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System -Name ConsentPromptBehaviorAdmin -Value 2"', shell=True, check=True) + subprocess.run( + 'powershell.exe -Command "Set-ItemProperty -Path HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System -Name ConsentPromptBehaviorAdmin -Value 2"', + shell=True, check=True) print("UAC settings updated.") + if __name__ == "__main__": configure_uac() From bab32877e659cd9e00e4814d139909a89b706111 Mon Sep 17 00:00:00 2001 From: Emily <147433015+EmilyButera@users.noreply.github.com> Date: Tue, 10 Dec 2024 14:53:56 -0600 Subject: [PATCH 89/93] Create ScriptyScript.sh Added my script to the CyberPatriot github --- Scripts/Linux/ScriptyScript.sh | 165 +++++++++++++++++++++++++++++++++ 1 file changed, 165 insertions(+) create mode 100644 Scripts/Linux/ScriptyScript.sh diff --git a/Scripts/Linux/ScriptyScript.sh b/Scripts/Linux/ScriptyScript.sh new file mode 100644 index 0000000..a10f41c --- /dev/null +++ b/Scripts/Linux/ScriptyScript.sh @@ -0,0 +1,165 @@ +#!/bin/bash + +LOG_FILE="/var/log/cyberpatriot.log" +touch $LOG_FILE +echo "CyberPatriot Script Started: $(date)" >> $LOG_FILE +echo "This script must be run as root" >> $LOG_FILE + +echo "Deleted all media files" >> $LOG_FILE + +find /home -name '*.mp3' -type f -delete + find /home -name '*.mov' -type f -delete + find /home -name '*.mp4' -type f -delete + find /home -name '*.avi' -type f -delete + find /home -name '*.mpg' -type f -delete + find /home -name '*.mpeg' -type f -delete + find /home -name '*.flac' -type f -delete + find /home -name '*.m4a' -type f -delete + find /home -name '*.flv' -type f -delete + find /home -name '*.ogg' -type f -delete + find /home -name '*.gif' -type f -delete + find /home -name '*.png' -type f -delete + find /home -name '*.jpg' -type f -delete + find /home -name '*.mp3' -type f -delete + find /home -name '*.tiff' -type f -delete + +#Remove prohibited Software +echo "removing prohibited software" >> $LOG_FILE +sudo apt remove ophcrack +sudo apt remove wireshark -y +sudo apt-get autoremove -y +sudo apt remove nmap +sudo apt remove nessus +sudo apt remove kismet +sudo apt remove metasploit +sudo apt remove aircrack-ng +sudo apt remove openvas +sudo apt remove sqlmap +sudo apt remove zenmap +sudo apt remove rainbow-crack +sudo apt remove ccleaner + +#Determines critical services +echo "Determining critical services and removing useless ones" >> $LOG_FILE + +#Fun stuff (SHOULD WORK ON BOTH DEBIAN AND UBUNTU) +clear +echo "Cleared command prompt" >> $LOG_FILE +unalias -a +echo "deleted all aliases" >> $LOG_FILE +printTime "All alias have been removed." >>$LOG_FILE + +clear +echo "root account locked" >> $LOG_FILE +usermod -L root +printTime "Root account has been locked. Use 'usermod -U root' to unlock it." + +clear +echo "Modified user privileges for bash history file" >> $LOG_FILE +chmod 640 .bash_history +printTime "Bash history file permissions set." + +clear +echo "Modified user privileges for Shadow files" >> $LOG_FILE +chmod 604 /etc/shadow +printTime "Read/Write permissions on shadow have been set." + +clear +echo "Checked for files and user folders not needed" >> $LOG_FILE +printTime "Check for any user folders that do not belong to any users in /home/." +ls -a /home/ >> $LOG_FILE + +clear +echo "Checked for any files for users that should not be admins" >> $LOG_FILE +printTime "Check for any files for users that should not be administrators in /etc/sudoers.d." +ls -a /etc/sudoers.d >> $LOG_FILE + +#Configuring Sysctl +echo "Configured Sysctl" >> $LOG_FILE +clear +echo > /etc/sysctl.conf +echo -e "# Controls IP packet forwarding\nnet.ipv4.ip_forward = 0\n\n# IP Spoofing protection\nnet.ipv4.conf.all.rp_filter = 1\nnet.ipv4.conf.default.rp_filter = 1\n\n# Ignore ICMP broadcast requests\nnet.ipv4.icmp_echo_ignore_broadcasts = 1\n\n# Disable source packet routing\nnet.ipv4.conf.all.accept_source_route = 0\nnet.ipv6.conf.all.accept_source_route = 0\nnet.ipv4.conf.default.accept_source_route = 0\nnet.ipv6.conf.default.accept_source_route = 0\n\n# Ignore send redirects\nnet.ipv4.conf.all.send_redirects = 0\nnet.ipv4.conf.default.send_redirects = 0\n\n# Block SYN attacks\nnet.ipv4.tcp_syncookies = 1\nnet.ipv4.tcp_max_syn_backlog = 2048\nnet.ipv4.tcp_synack_retries = 2\nnet.ipv4.tcp_syn_retries = 5\n\n# Log Martians\nnet.ipv4.conf.all.log_martians = 1\nnet.ipv4.icmp_ignore_bogus_error_responses = 1\n\n# Ignore ICMP redirects\nnet.ipv4.conf.all.accept_redirects = 0\nnet.ipv6.conf.all.accept_redirects = 0\nnet.ipv4.conf.default.accept_redirects = 0\nnet.ipv6.conf.default.accept_redirects = 0\n\n# Ignore Directed pings\nnet.ipv4.icmp_echo_ignore_all = 1\n\n# Accept Redirects? No, this is not router\nnet.ipv4.conf.all.secure_redirects = 0\n\n# Log packets with impossible addresses to kernel log? yes\nnet.ipv4.conf.default.secure_redirects = 0\n\n########## IPv6 networking start ##############\n# Number of Router Solicitations to send until assuming no routers are present.\n# This is host and not router\nnet.ipv6.conf.default.router_solicitations = 0\n\n# Accept Router Preference in RA?\nnet.ipv6.conf.default.accept_ra_rtr_pref = 0\n\n# Learn Prefix Information in Router Advertisement\nnet.ipv6.conf.default.accept_ra_pinfo = 0\n\n# Setting controls whether the system will accept Hop Limit settings from a router advertisement\nnet.ipv6.conf.default.accept_ra_defrtr = 0\n\n#router advertisements can cause the system to assign a global unicast address to an interface\nnet.ipv6.conf.default.autoconf = 0\n\n#how many neighbor solicitations to send out per address?\nnet.ipv6.conf.default.dad_transmits = 0\n\n# How many global unicast IPv6 addresses can be assigned to each interface? +net.ipv6.conf.default.max_addresses = 1\n\n########## IPv6 networking ends ##############" >> /etc/sysctl.conf +sysctl -p >> /dev/null +printTime "Sysctl has been configured." + +#Decide whether or not to disable IPv6 +echo -e "\n\n# Disable IPv6\nnet.ipv6.conf.all.disable_ipv6 = 1\nnet.ipv6.conf.default.disable_ipv6 = 1\nnet.ipv6.conf.lo.disable_ipv6 = 1" >> /etc/sysctl.conf +sysctl -p >> /dev/null +printTime "IPv6 has been disabled." +echo "IPv6 disapled" >> $LOG_FILE + +#finding and removing backdoors +echo "Fixed and removed backdoors" >> $LOG_FILE +wget http://downloads.sourceforge.net/project/rkhunter/rkhunter/1.4.2/rkhunter-1.4.2.tar.gz +tar xfz rkhunter-1.4.2.tar.gz +sudo ./rkhunter-1.4.2/installer.sh --layout default --install +sudo ./rkhunter-1.4.2/installer.sh --layout default --install +sudo /usr/local/bin/rkhunter --update --propupd +sudo /usr/local/bin/rkhunter --check + +#Check for prohibeted software, as well as stops prohibited software from running. +echo "Checked for prohibited software" >> $LOG_FILE +sudo systemctl stop nginx +sudo systemctl disable nginx + +#games +echo "Deleted games" >> $LOG_FILE +sudo apt-get purge -y 0ad 0ad-data 0ad-data-common 2048-qt 3dchess 4digits 7kaa 7kaa-data a7xpg a7xpg-data aajm abe abe-data ace-of-penguins acm adanaxisgpl adanaxisgpl-data adonthell adonthell-data airstrike airstrike-common aisleriot alex4 alex4-data alien-arena alien-arena-data alien-arena-server alienblaster alienblaster-data allure amoebax amoebax-data amphetamine amphetamine-data an anagramarama anagramarama-data angband angband-audio angband-data angrydd animals antigravitaattori ardentryst armagetronad armagetronad-common armagetronad-dedicated asc asc-data asc-music asciijump assaultcube assaultcube-data astromenace astromenace-data-src asylum asylum-data atanks atanks-data atom4 atomix atomix-data attal attal-themes-medieval auralquiz balder2d balder2d-data ballerburg ballz ballz-data ballz-dbg bambam barrage bastet bb bear-factory beneath-a-steel-sky berusky berusky-data berusky2 berusky2-data between billard-gl billard-gl-data biloba biloba-data biniax2 biniax2-data black-box blobandconquer blobandconquer-data blobby blobby-data blobby-server bloboats blobwars blobwars-data blockattack blockout2 blocks-of-the-undead blocks-of-the-undead-data bombardier bomber bomberclone bomberclone-data boswars boswars-data bouncy bovo brainparty brainparty-data briquolo briquolo-data brutalchess bsdgames bsdgames-nonfree btanks btanks-data bubbros bucklespring bucklespring-data bugsquish bumprace bumprace-data burgerspace bve-route-cross-city-south bve-train-br-class-323 bve-train-br-class-323-3dcab bygfoot bygfoot-data bzflag bzflag-client bzflag-data bzflag-server cappuccino caveexpress caveexpress-data cavepacker cavepacker-data cavezofphear ceferino ceferino-data cgoban chessx childsplay childsplay-alphabet-sounds-bg childsplay-alphabet-sounds-ca childsplay-alphabet-sounds-de childsplay-alphabet-sounds-el childsplay-alphabet-sounds-en-gb childsplay-alphabet-sounds-es childsplay-alphabet-sounds-fr childsplay-alphabet-sounds-it childsplay-alphabet-sounds-nb childsplay-alphabet-sounds-nl childsplay-alphabet-sounds-pt childsplay-alphabet-sounds-ro childsplay-alphabet-sounds-ru childsplay-alphabet-sounds-sl childsplay-alphabet-sounds-sv chipw chocolate-common chocolate-doom chromium-bsu chromium-bsu-data circuslinux circuslinux-data colobot colobot-common colobot-common-sounds colobot-common-textures colorcode colossal-cave-adventure connectagram connectagram-data cookietool corsix-th corsix-th-data cowsay cowsay-off crack-attack crafty crafty-bitmaps crafty-books-medium crafty-books-medtosmall crafty-books-small crawl crawl-common crawl-tiles crawl-tiles-data crimson criticalmass criticalmass-data crossfire-client crossfire-client-images crossfire-client-sounds crossfire-common crossfire-maps crossfire-maps crossfire-maps-small crossfire-server crrcsim crrcsim-data csmash csmash-data csmash-demosong cube2 cube2-data cube2-server cultivation curseofwar cutemaze cuyo cuyo-data cyphesis-cpp cyphesis-cpp-clients cyphesis-cpp-mason cytadela cytadela-data d1x-rebirth d2x-rebirth dangen darkplaces darkplaces-server ddnet ddnet-data ddnet-server ddnet-tools dds deal dealer defendguin defendguin-data desmume deutex dhewm3 dhewm3-d3xp dhewm3-doom3 dizzy dodgindiamond2 dolphin-emu dolphin-emu-data doom-wad-shareware doomsday doomsday-common doomsday-data doomsday-server dopewars dopewars-data dossizola dossizola-data drascula drascula-french drascula-german drascula-italian drascula-music drascula-spanish dreamchess dreamchess-data dustracing2d dustracing2d-data dvorak7min dwarf-fortress dwarf-fortress-data eboard eboard-extras-pack1 edgar edgar-data efp einstein el-ixir ember ember-media empire empire-hub empire-lafe endless-sky endless-sky-data endless-sky-high-dpi enemylines3 enemylines7 enigma enigma-data epiphany epiphany-data etoys etqw etqw-server etw etw-data excellent-bifurcation extremetuxracer extremetuxracer-data exult exult-studio ezquake fairymax fb-music-high ffrenzy fgo fgrun fheroes2-pkg filler fillets-ng fillets-ng-data fillets-ng-data-cs fillets-ng-data-nl filters five-or-more fizmo-common fizmo-console fizmo-ncursesw fizmo-sdl2 flare flare-data flare-engine flare-game flight-of-the-amazon-queen flightgear flightgear-data-ai flightgear-data-all flightgear-data-base flightgear-data-models flightgear-phi flobopuyo fltk1.1-games fltk1.3-games foobillardplus foobillardplus-data fortunate.app fortune-anarchism fortune-mod fortune-zh fortunes fortunes-bg fortunes-bofh-excuses fortunes-br fortunes-cs fortunes-de fortunes-debian-hints fortunes-eo fortunes-eo-ascii fortunes-eo-iso3 fortunes-es fortunes-es-off fortunes-fr fortunes-ga fortunes-it fortunes-it-off fortunes-mario fortunes-min fortunes-off fortunes-pl fortunes-ru fortunes-spam fortunes-zh four-in-a-row freealchemist freecell-solver-bin freeciv freeciv-client-extras freeciv-client-gtk freeciv-client-gtk3 freeciv-client-qt freeciv-client-sdl freeciv-data freeciv-server freeciv-sound-standard freecol freedink freedink-data freedink-dfarc freedink-dfarc-dbg freedink-engine freedink-engine-dbg freedm freedoom freedroid freedroid-data freedroidrpg freedroidrpg-data freegish freegish-data freeorion freeorion-data freespace2 freespace2-launcher-wxlauncher freesweep freetennis freetennis-common freevial fretsonfire fretsonfire-game fretsonfire-songs-muldjord fretsonfire-songs-sectoid frogatto frogatto-data frotz frozen-bubble frozen-bubble-data fruit funguloids funguloids-data funnyboat gamazons game-data-packager game-data-packager-runtime gameclock gamine gamine-data garden-of-coloured-lights garden-of-coloured-lights-data gargoyle-free gav gav-themes gbrainy gcompris gearhead gearhead-data gearhead-sdl gearhead2 gearhead2-data gearhead2-sdl geekcode geki2 geki3 gemdropx gemrb gemrb-baldurs-gate gemrb-baldurs-gate-2 gemrb-baldurs-gate-2-data gemrb-baldurs-gate-data gemrb-data gemrb-icewind-dale gemrb-icewind-dale-2 gemrb-icewind-dale-2-data gemrb-icewind-dale-data gemrb-planescape-torment gemrb-planescape-torment-data geneatd gfceu gfpoken gl-117 gl-117-data glaurung glhack glob2 glob2-data glpeces glpeces-data gltron gmchess gmult gnome-2048 gnome-mines gnome-aisleriot gnome-breakout gnome-cards-data gnome-chess gnome-games-app gnome-klotski gnome-mahjongg gnome-mastermind gnome-mines gnome-nibbles gnome-robots gnome-sudoku gnome-tetravex gnubg gnubg-data gnubik gnuboy-sdl gnuboy-x gnuchess gnuchess-book gnudoq gnugo gnujump gnujump-data gnuminishogi gnurobbo gnurobbo-data gnushogi golly gomoku.app gplanarity gpsshogi gpsshogi-data granatier granule gravitation gravitywars greed grhino grhino-data gridlock.app groundhog gsalliere gtans gtkballs gtkboard gtkpool gunroar gunroar-data gweled hachu hannah hannah-data hearse hedgewars hedgewars-data heroes heroes-data heroes-sound-effects heroes-sound-tracks hex-a-hop hex-a-hop-data hexalate hexxagon higan hitori hoichess holdingnuts holdingnuts-server holotz-castle holotz-castle-data holotz-castle-editor hyperrogue hyperrogue-music iagno icebreaker ii-esu infon-server infon-viewer instead instead-data ioquake3 ioquake3-server jag jag-data jester jigzo jigzo-data jmdlx jumpnbump jumpnbump-levels jzip kajongg kanagram kanatest kapman katomic kawari8 kball kball-data kblackbox kblocks kbounce kbreakout kcheckers kdegames-card-data kdegames-card-data-kf5 kdegames-mahjongg-data-kf5 kdiamond ketm ketm-data kfourinline kgoldrunner khangman kigo kiki-the-nano-bot kiki-the-nano-bot-data kildclient killbots kiriki kjumpingcube klickety klines kmahjongg kmines knavalbattle knetwalk knights kobodeluxe kobodeluxe-data kolf kollision komi konquest koules kpat krank kraptor kraptor-data kreversi kshisen ksirk ksnakeduel kspaceduel ksquares ksudoku ktuberling kubrick laby lambdahack late late-data lbreakout2 lbreakout2-data lgc-pg lgeneral lgeneral-data libatlas-cpp-0.6-tools libgemrb libmgba libretro-beetle-pce-fast libretro-beetle-psx libretro-beetle-vb libretro-beetle-wswan libretro-bsnes-mercury-accuracy libretro-bsnes-mercury-balanced libretro-bsnes-mercury-performance libretro-desmume libretro-gambatte libretro-genesisplusgx libretro-mgba libretro-mupen64plus libretro-nestopia libretro-snes9x lierolibre lierolibre-data lightsoff lightyears lincity lincity-ng lincity-ng-data liquidwar liquidwar-data liquidwar-server littlewizard littlewizard-data lmarbles lmemory lolcat londonlaw lordsawar lordsawar-data love lskat ltris lugaru lugaru-data luola luola-data luola-levels luola-nostalgy lure-of-the-temptress macopix-gtk2 madbomber madbomber-data maelstrom magicmaze magicor magicor-data magictouch mah-jong mame mame-data mame-extra manaplus manaplus-data mancala marsshooter marsshooter-data matanza mazeofgalious mazeofgalious-data mednafen mednaffe megaglest megaglest-data meritous meritous-data mgba-common mgba-qt mgba-sdl mgt miceamaze micropolis micropolis-data minetest minetest-data minetest-mod-advspawning minetest-mod-animalmaterials minetest-mod-animals minetest-mod-character-creator minetest-mod-craftguide minetest-mod-homedecor minetest-mod-maidroid minetest-mod-mesecons minetest-mod-mobf minetest-mod-mobf-core minetest-mod-mobf-trap minetest-mod-moreblocks minetest-mod-moreores minetest-mod-nether minetest-mod-pipeworks minetest-mod-player-3d-armor minetest-mod-quartz minetest-mod-torches minetest-mod-unifieddyes minetest-mod-worldedit minetest-server mirrormagic mirrormagic-data mokomaze monopd monsterz monsterz-data moon-buggy moon-lander moon-lander-data moria morris mousetrap mrboom mrrescue mttroff mu-cade mu-cade-data mudlet multitet mupen64plus-audio-all mupen64plus-audio-sdl mupen64plus-data mupen64plus-input-all mupen64plus-input-sdl mupen64plus-qt mupen64plus-rsp-all mupen64plus-rsp-hle mupen64plus-rsp-z64 mupen64plus-ui-console mupen64plus-video-all mupen64plus-video-arachnoid mupen64plus-video-glide64 mupen64plus-video-glide64mk2 mupen64plus-video-rice mupen64plus-video-z64 nestopia nethack-common nethack-console nethack-el nethack-lisp nethack-x11 netmaze netpanzer netpanzer-data netris nettoe neverball neverball-common neverball-data neverputt neverputt-data nexuiz nexuiz-data nexuiz-music nexuiz-server nexuiz-textures nikwi nikwi-data ninix-aya ninvaders njam njam-data noiz2sa noiz2sa-data nsnake nudoku numptyphysics ogamesim ogamesim-www omega-rpg oneisenough oneko onscripter open-adventure open-invaders open-invaders-data openarena openarena-081-maps openarena-081-misc openarena-081-players openarena-081-players-mature openarena-081-textures openarena-085-data openarena-088-data openarena-data openarena-oacmp1 openarena-server openbve-data opencity opencity-data openclonk openclonk-data openlugaru openlugaru-data openmw openmw-cs openmw-data openmw-launcher openpref openssn openssn-data openttd openttd-data openttd-opengfx openttd-openmsx openttd-opensfx opentyrian openyahtzee orbital-eunuchs-sniper orbital-eunuchs-sniper-data osmose-emulator out-of-order overgod overgod-data pachi pachi-data pacman pacman4console palapeli palapeli-data pangzero parsec47 parsec47-data passage pathogen pathological pax-britannica pax-britannica-data pcsx2 pcsxr peg-e peg-solitaire pegsolitaire penguin-command pente pentobi performous performous-tools pescetti petris pgn-extract phalanx phlipple phlipple-data pianobooster picmi pinball pinball-data pinball-dev pingus pingus-data pink-pony pink-pony-data pioneers pioneers-console pioneers-console-data pioneers-data pioneers-metaserver pipenightdreams pipenightdreams-data pipewalker piu-piu pixbros pixfrogger planarity planetblupi planetblupi-common planetblupi-music-midi planetblupi-music-ogg plee-the-bear plee-the-bear-data pokemmo-installer pokerth pokerth-data pokerth-server polygen polygen-data polyglot pong2 powder powermanga powermanga-data pq prboom-plus prboom-plus-game-server primrose projectl purity purity-ng purity-off pybik pybik-bin pybridge pybridge-common pybridge-server pykaraoke pykaraoke-bin pynagram pyracerz pyscrabble pyscrabble-common pyscrabble-server pysiogame pysolfc pysolfc-cardsets pysycache pysycache-buttons-beerabbit pysycache-buttons-crapaud pysycache-buttons-ice pysycache-buttons-wolf pysycache-click-dinosaurs pysycache-click-sea pysycache-dblclick-appleandpear pysycache-dblclick-butterfly pysycache-i18n pysycache-images pysycache-move-animals pysycache-move-food pysycache-move-plants pysycache-move-sky pysycache-move-sports pysycache-puzzle-cartoons pysycache-puzzle-photos pysycache-sounds python-pykaraoke python-renpy qgo qonk qstat qtads quadrapassel quake quake-server quake2 quake2-server quake3 quake3-data quake3-server quake4 quake4-server quakespasm quarry qxw rafkill rafkill-data raincat raincat-data randtype rbdoom3bfg redeclipse redeclipse-common redeclipse-data redeclipse-server reminiscence renpy renpy-demo renpy-thequestion residualvm residualvm-data ri-li ri-li-data ricochet rlvm robocode robotfindskitten rockdodger rocksndiamonds rolldice rott rrootage rrootage-data rtcw rtcw-common rtcw-server runescape salliere sandboxgamemaker sauerbraten sauerbraten-server scid scid-data scid-rating-data scid-spell-data scorched3d scorched3d-data scottfree scummvm scummvm-data scummvm-tools sdl-ball sdl-ball-data seahorse-adventures searchandrescue searchandrescue-common searchandrescue-data sgt-launcher sgt-puzzles shogivar shogivar-data simutrans simutrans-data simutrans-makeobj simutrans-pak128.britain simutrans-pak64 singularity singularity-music sjaakii sjeng sl slashem slashem-common slashem-gtk slashem-sdl slashem-x11 slimevolley slimevolley-data slingshot sludge-engine sm snake4 snowballz solarwolf sopwith spacearyarya spacezero speedpad spellcast sponc spout spring spring-common spring-javaai spring-maps-kernelpanic spring-mods-kernelpanic springlobby starfighter starfighter-data starvoyager starvoyager-data stax steam steam-devices steam-installer steamcmd stockfish stormbaancoureur stormbaancoureur-data sudoku supertransball2 supertransball2-data supertux supertux-data supertuxkart supertuxkart-data swell-foop tagua tagua-data tali tanglet tanglet-data tatan tdfsb tecnoballz tecnoballz-data teeworlds teeworlds-data teeworlds-server tenace tenmado tennix tetrinet-client tetrinet-server tetrinetx tetzle tf tf5 tictactoe-ng tint tintin++ tinymux titanion titanion-data toga2 tomatoes tomatoes-data tome toppler torcs torcs-data torus-trooper torus-trooper-data tourney-manager trackballs trackballs-data transcend treil trigger-rally trigger-rally-data triplane triplea trophy trophy-data trophy-dbg tumiki-fighters tumiki-fighters-data tuxfootball tuxmath tuxmath-data tuxpuck tuxtype tuxtype-data tworld tworld-data typespeed uci2wb ufoai ufoai-common ufoai-data ufoai-maps ufoai-misc ufoai-music ufoai-server ufoai-sound ufoai-textures uhexen2 uhexen2-common uligo unknown-horizons uqm uqm-content uqm-music uqm-russian uqm-voice val-and-rick val-and-rick-data vbaexpress vcmi vectoroids viruskiller visualboyadvance vodovod vor warmux warmux-data warmux-servers warzone2100 warzone2100-data warzone2100-music werewolf wesnoth wesnoth-1.12 wesnoth-1.12-aoi wesnoth-1.12-core wesnoth-1.12-data wesnoth-1.12-did wesnoth-1.12-dm wesnoth-1.12-dw wesnoth-1.12-ei wesnoth-1.12-httt wesnoth-1.12-l wesnoth-1.12-low wesnoth-1.12-music wesnoth-1.12-nr wesnoth-1.12-server wesnoth-1.12-sof wesnoth-1.12-sotbe wesnoth-1.12-thot wesnoth-1.12-tools wesnoth-1.12-trow wesnoth-1.12-tsg wesnoth-1.12-ttb wesnoth-1.12-utbs wesnoth-core wesnoth-music wfut whichwayisup widelands widelands-data wing wing-data wizznic wizznic-data wmpuzzle wolf4sdl wordplay wordwarvi wordwarvi-sound xabacus xabacus xball xbill xblast-tnt xblast-tnt-images xblast-tnt-levels xblast-tnt-models xblast-tnt-musics xblast-tnt-sounds xboard xbomb xbubble xbubble-data xchain xcowsay xdemineur xdesktopwaves xevil xfireworks xfishtank xflip xfrisk xgalaga xgalaga++ xgammon xinv3d xjig xjokes xjump xletters xmabacus xmahjongg xmille xmoto xmoto-data xmountains xmpuzzles xonix xpat2 xpenguins xphoon xpilot-extra xpilot-ng xpilot-ng-client-sdl xpilot-ng-client-x11 xpilot-ng-common xpilot-ng-server xpilot-ng-utils xpuzzles xqf xracer xracer-tools xscavenger xscorch xscreensaver-screensaver-dizzy xshisen xshogi xskat xsok xsol xsoldier xstarfish xsystem35 xteddy xtron xvier xwelltris xye xye-data xzip yahtzeesharp yamagi-quake2 yamagi-quake2-core zangband zangband-data zatacka zaz zaz-data zec zivot zoom-player gameconqueror + +# Enable firewall + +#installs firewall +sudo apt install ufw + +#gives firewall status +sudo ufw status verbose +sudo ufw status >> $LOG_FILE + +#configures settings +sudo ufw default deny incoming +sudo ufw enable + +#allows services +sudo ufw allow ssh +sudo ufw allow 4422/tcp + +#denies specific ports +enable #firewall on +sudo ufw deny 23 #block Telnet +sudo ufw deny 515 #block printer port +sudo ufw allow log 22/tcp +sudo ufw allow 139 +sudo ufw allow 445 +sudo ufw allow 137 +sudo ufw allow 138 +sudo ufw deny 21 +sudo ufw deny cups + +#disables these two services +sudo apt-get purge -y cups +sudo apt-get purge -y bluetooth + +echo "Firewall enabled and setup" >> $LOG_FILE + +#start Open SSH at boot +sudo update-rc.d ssh enable +/etc/rc3.d/ +echo "SSH Starts at boot" >> $LOG_FILE + +#stop services +sudo systemctl stop httpd +sudo systemctl stop apache2 +sudo systemctl stop nginx +sudo systemctl disable nginx +echo "Stopped httpd, apache2, nginx" >> $LOG_FILE + +#Disabling root login +sudo sed -i 's/PermitRootLogin yes/PermitRootLogin no/g' /etc/ssh/sshd_config +sudo sed -i 's/nullok/ /g' /etc/pam.d/common_auth + +echo "System updated and upgraded" >>$LOG_FILE +#updates system + sudo apt update + sudo apt upgrade + sudo reboot \ No newline at end of file From 4725df43e94495eb4d615a8b0702176c6f460d84 Mon Sep 17 00:00:00 2001 From: Emily <147433015+EmilyButera@users.noreply.github.com> Date: Tue, 10 Dec 2024 14:57:56 -0600 Subject: [PATCH 90/93] Update ScriptyScript.sh Updated apache disabling --- Scripts/Linux/ScriptyScript.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/Scripts/Linux/ScriptyScript.sh b/Scripts/Linux/ScriptyScript.sh index a10f41c..fdfa4b7 100644 --- a/Scripts/Linux/ScriptyScript.sh +++ b/Scripts/Linux/ScriptyScript.sh @@ -152,6 +152,7 @@ sudo systemctl stop httpd sudo systemctl stop apache2 sudo systemctl stop nginx sudo systemctl disable nginx +sudo systemctl purge apache2 echo "Stopped httpd, apache2, nginx" >> $LOG_FILE #Disabling root login From 45ae31d1770106a76f60587ee387c65ed94ca886 Mon Sep 17 00:00:00 2001 From: Jordan A Date: Thu, 18 Sep 2025 08:47:25 -0500 Subject: [PATCH 91/93] Update Checklist fixed a couple formatting errors --- Windows CyberPatriot Checklist.txt | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/Windows CyberPatriot Checklist.txt b/Windows CyberPatriot Checklist.txt index eaca322..475b5c4 100644 --- a/Windows CyberPatriot Checklist.txt +++ b/Windows CyberPatriot Checklist.txt @@ -48,7 +48,7 @@ Competition Checklist: * Run a quick scan on the machine with either Malware Removal Tool (Malwarebytes) or Windows Security. (either win+r > mrt > Quick Scan or Settings > Update and Security > Windows Security > Quick Scan) * Password security (win+r > gpedit.msc > Account Policy > Password Policy) OR (win+r > gpedit.msc > Account Policy > Account Lockout Policy) - Enforce password history: 24 + * Enforce password history: 24 * Maximum password age: 60 * Minimum password age: 1 * Minimum password length: 10 @@ -75,9 +75,9 @@ For updating browsers For group policy security settings - *Don't display last user name on login screen - *Require Ctrl+Alt+Del before signing in - *Ty got too lazy to add the rest :/ + * Don't display last user name on login screen + * Require Ctrl+Alt+Del before signing in + * Ty got too lazy to add the rest :/ Registry Editor hives explained (if you ever need to use it) * HKEY_CURRENT_USER (HKCU) - @@ -103,3 +103,4 @@ Removing Malware (You will probably only need step 1) *Process Monitor(Gives detailed info about file system, registry, and thread activity)(https://learn.microsoft.com/en-us/sysinternals/downloads/procmon) *TCPView(lists all programs on the computer that are connected to a remote computer)(https://learn.microsoft.com/en-us/sysinternals/downloads/tcpview) + From 1cf3786a99a583ac35bf84cdd8c0a0624025adf7 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Fri, 24 Oct 2025 22:12:51 -0500 Subject: [PATCH 92/93] Das erstellte Windows-Skript wird Ihren Computer definitiv blockieren --- .../Firewall/FirewallRules.psm1 | 467 ++++++++++++ .../Firewall/FirewallUp.psm1 | 22 + .../Windows/MasterScriptStuff/Log/Log.psm1 | 9 + .../MasterScript-Combined.ps1 | 706 ++++++++++++++++++ .../MasterScriptStuff/MasterScript.ps1 | 50 ++ .../MasterScriptStuff/SSH/SSHConf.psm1 | 12 + .../MasterScriptStuff/SecPol/GetSecPol.psm1 | 24 + .../MasterScriptStuff/SecPol/SetSecPol.psm1 | 13 + .../Services/SetServices.psm1 | 276 +++++++ .../MasterScriptStuff/Task/DisableTask.psm1 | 10 + .../MasterScriptStuff/lib/Event Audit.json | 11 + .../MasterScriptStuff/lib/System Access.json | 14 + 12 files changed, 1614 insertions(+) create mode 100644 Scripts/Windows/MasterScriptStuff/Firewall/FirewallRules.psm1 create mode 100644 Scripts/Windows/MasterScriptStuff/Firewall/FirewallUp.psm1 create mode 100644 Scripts/Windows/MasterScriptStuff/Log/Log.psm1 create mode 100644 Scripts/Windows/MasterScriptStuff/MasterScript-Combined.ps1 create mode 100644 Scripts/Windows/MasterScriptStuff/MasterScript.ps1 create mode 100644 Scripts/Windows/MasterScriptStuff/SSH/SSHConf.psm1 create mode 100644 Scripts/Windows/MasterScriptStuff/SecPol/GetSecPol.psm1 create mode 100644 Scripts/Windows/MasterScriptStuff/SecPol/SetSecPol.psm1 create mode 100644 Scripts/Windows/MasterScriptStuff/Services/SetServices.psm1 create mode 100644 Scripts/Windows/MasterScriptStuff/Task/DisableTask.psm1 create mode 100644 Scripts/Windows/MasterScriptStuff/lib/Event Audit.json create mode 100644 Scripts/Windows/MasterScriptStuff/lib/System Access.json diff --git a/Scripts/Windows/MasterScriptStuff/Firewall/FirewallRules.psm1 b/Scripts/Windows/MasterScriptStuff/Firewall/FirewallRules.psm1 new file mode 100644 index 0000000..271d4f3 --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/Firewall/FirewallRules.psm1 @@ -0,0 +1,467 @@ +function set-FirewallRule { + #Firewall script +#Disable every pre-existing rule +Set-NetFirewallRule * -Enabled False -Action NotConfigured + +#Block multiple Windows features by pre-existing rules +Set-NetFirewallRule -DisplayGroup "AllJoyn Router","*BranchCache*","Cast to Device functionality","Connect","Cortana","Delivery Optimization","DIAL protocol server","Feedback Hub","File and Printer Sharing","Get Office","Groove Music","HomeGroup","iSCSI Service","mDNS","Media Center Extenders","Microsoft Edge","Microsoft Photos","Microsoft Solitaire Collection","Movies & TV","MSN Weather","Network Discovery","OneNote","*Wi-Fi*","Paint 3D","Proximity Sharing","*Remote*","Secure Socket Tunneling Protocol","*Skype*","SNMP Trap","Store","*Smart Card*","Virtual Machine Monitoring","Windows Collaboration Computer Name Registration Service","*Windows Media Player*","Windows Peer to Peer Collaboration Foundation","Windows View 3D Preview","*Wireless*","*WFD*","*Xbox*","3D Builder","Captive Portal Flow","Take a Test","Wallet" -Action Block -Enabled True -Profile Any + +#Block multiple insecure protocols by pre-existing rules +Set-NetFirewallRule -DisplayName "*IPv6*","*ICMP*","*SMB*","*UPnP*","*FTP*","*Telnet*" -Action Block -Enabled True -Profile Any + +#Block multiple ports with new rule +New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 20-21 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 22 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 23 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "HTTP" -LocalPort 80 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "TorPark onion routing" -LocalPort 81 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "TorPark control" -LocalPort 82 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "RTelnet" -LocalPort 107 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "RTelnet" -LocalPort 107 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "DHCPv6" -LocalPort 546-547 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "DHCPv6" -LocalPort 546-547 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Flash" -LocalPort 843 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "B.net (Free HK)" -LocalPort 1119 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "B.net (Free HK)" -LocalPort 1119 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Kazaa" -LocalPort 1214 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Kazaa" -LocalPort 1214 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "WASTE" -LocalPort 1337 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Civ" -LocalPort 1492 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Garena" -LocalPort 1513 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Garena" -LocalPort 1513 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "iSketch" -LocalPort 1626-1627 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Defunct RADIUS Ports" -LocalPort 1645-1646 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Windward" -LocalPort 1707 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Windward" -LocalPort 1707 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "America's Army" -LocalPort 1716 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Microsoft Media Services" -LocalPort 1755 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Microsoft Media Services" -LocalPort 1755 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "SSDP" -LocalPort 1900 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Macro Flash" -LocalPort 1935 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Macro Flash" -LocalPort 1935 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Netop" -LocalPort 1970 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Netop" -LocalPort 1970 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Civ 4" -LocalPort 2033 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Civ 4" -LocalPort 2033 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Warzone 2100" -LocalPort 2100 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Apple Notifs" -LocalPort 2195 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Apple Notifs Feedback" -LocalPort 2196 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "ArmA/Halo" -LocalPort 2302-2305 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "AIM/Ghost" -LocalPort 2351-2368 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Ultima Online" -LocalPort 2593 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Ultima Online" -LocalPort 2593 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Ultima Online 2" -LocalPort 2599 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Ultima Online 2" -LocalPort 2599 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "iSync" -LocalPort 3004 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Xbox LIVE" -LocalPort 3074 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Xbox LIVE" -LocalPort 3074 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "iSCSI" -LocalPort 3260 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "iSCSI" -LocalPort 3260 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "RDP" -LocalPort 3389 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "RDP" -LocalPort 3389 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "PlayStation" -LocalPort 3479-3480 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "PlayStation" -LocalPort 3479-3480 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Cyc" -LocalPort 3645 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Cyc" -LocalPort 3645 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BF4" -LocalPort 3659 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Blizzard games/Club Penguin" -LocalPort 3724 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Blizzard games/Club Penguin" -LocalPort 3724 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "WarMUX" -LocalPort 3826 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "WarMUX" -LocalPort 3826 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Warframe" -LocalPort 3960 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Warframe again" -LocalPort 3962 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "OpenTTD" -LocalPort 3978-3979 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "OpenTTD" -LocalPort 3978-3979 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Diablo 2" -LocalPort 4000 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Diablo 2" -LocalPort 4000 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Microsoft Ants" -LocalPort 4001 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Amazon Echo" -LocalPort 4070 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Amazon Echo" -LocalPort 4070 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Microsoft Remote Web Workplace admin" -LocalPort 4125 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Apprentice" -LocalPort 4747 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Many things" -LocalPort 5000 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Many things" -LocalPort 5000 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "LoL" -LocalPort 5000-5500 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Neverwinter Nights" -LocalPort 5121 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Apple Notif 2" -LocalPort 5223 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Outlaws" -LocalPort 5310 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "PostgreSQL" -LocalPort 5432 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Freeciv" -LocalPort 5556 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Freeciv" -LocalPort 5556 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "TeamViewer" -LocalPort 5938 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "TeamViewer" -LocalPort 5938 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "More b.net/CP 2 (Free HK)" -LocalPort 6112 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "More b.net/CP 2 (Free HK)" -LocalPort 6112 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "B.net/Club penguin 3" -LocalPort 6113 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6881-6887 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6881-6887 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6888 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6888 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6889-6900 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6889-6900 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Windows Live Messenger" -LocalPort 6891-6900 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Windows Live Messenger" -LocalPort 6891-6900 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6901 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6901 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6902-6968 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6902-6968 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "BitTorrent tracker" -LocalPort 6969 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "HTTP Bittorrent" -LocalPort 7000 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Enemy Territory: Quake Wars" -LocalPort 7133 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Tibia" -LocalPort 7171 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "WatchMe" -LocalPort 7272 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "WatchMe" -LocalPort 7272 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Rise: The Vieneo Province" -LocalPort 7473 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Saratoga FTP" -LocalPort 7542 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Saratoga FTP" -LocalPort 7542 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 7707-7708 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 7717 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Just Cause 2, Terraria, GTA:SA" -LocalPort 7777 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Just Cause 2, Terraria, GTA:SA" -LocalPort 7777 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Unreal Tournament" -LocalPort 7777-7788 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Unreal Tournament" -LocalPort 7777-7788 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 8075 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "MapleStory" -LocalPort 8484 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "QBittorrent" -LocalPort 9000 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Tor" -LocalPort 9030 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Tor" -LocalPort 9050-9051 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Clash of Clans" -LocalPort 9339 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Club Penguin" -LocalPort 9875 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "CrossFire" -LocalPort 10009 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "CrossFire" -LocalPort 10009 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Touhou" -LocalPort 10080 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Lock On: Modern Air Combat" -LocalPort 10308 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Lock On: Modern Air Combat" -LocalPort 10308 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "SWAT 4" -LocalPort 10480 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "SWAT 4" -LocalPort 10480 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Farming Simulator 2011" -LocalPort 10823 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Savage: Battle for Newerth" -LocalPort 11235 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Savage: Battle for Newerth" -LocalPort 11235 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "OpenRCT2" -LocalPort 11753 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 12012-12013 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 12012-12013 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Second Life" -LocalPort 12035 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Second Life" -LocalPort 12043 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Second Life" -LocalPort 12046 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Cube World" -LocalPort 12345 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Cube World" -LocalPort 12345 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Second Life" -LocalPort 13000-13050 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "CrossFire (again)" -LocalPort 13008 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "CrossFire (again)" -LocalPort 13008 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Battlefield 1942" -LocalPort 14567 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Battlefield Vietnam" -LocalPort 15567 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "XPilot" -LocalPort 15345 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "XPilot" -LocalPort 15345 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Project Zomboid" -LocalPort 16261 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Project Zomboid" -LocalPort 16261 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Battlefield 2" -LocalPort 16567 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Worms" -LocalPort 17011 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Monero P2P" -LocalPort 18080 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18200 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18200 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18201 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18201 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18206 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18206 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18300-18301 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18300-18301 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18306 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18306 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Bitcoin" -LocalPort 18333 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18400-18401 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18400-18401 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18505-18506 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18505-18506 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "X-BEAT" -LocalPort 18605-18606 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "X-BEAT" -LocalPort 18605-18606 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Minecraft: Bedrock Edition" -LocalPort 19132-19133 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 20560 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 20560 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "0 A.D. Empires Ascendant" -LocalPort 20595 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Duke Nukem 3D" -LocalPort 23513 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Duke Nukem 3D" -LocalPort 23513 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "StepMania: Online: DDR" -LocalPort 24842 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "StepMania: Online: DDR" -LocalPort 24842 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Minecraft" -LocalPort 25565 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Minecraft" -LocalPort 25565 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Minecraft" -LocalPort 25575 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Quake, EVE Online, Xonotic" -LocalPort 26000 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Quake, EVE Online, Xonotic" -LocalPort 26000 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "EVE Online" -LocalPort 26900-26901 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "QuakeWorld" -LocalPort 27000-27006 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27000-27015 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Unturned" -LocalPort 27015-27018 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27015-27030 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27015-27030 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Magicka" -LocalPort 27016 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Magicka" -LocalPort 27016 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27031 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27036-27037 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27036-27037 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "QuakeWorld" -LocalPort 27500-27900 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Quake II" -LocalPort 27901-27910 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "OpenArena" -LocalPort 27950 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Enemy Territoy, Quake III, Quake Live" -LocalPort 27960-27969 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Starsiege: Tribes" -LocalPort 28001 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Starsiege: Tribes" -LocalPort 28001 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Rust" -LocalPort 28015 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "AssaultCube Reloaded" -LocalPort 28770-28771 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Cube 2: Sauerbraten" -LocalPort 28785-28786 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 28852 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 28852 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 28910 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 28910 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Call of Duty" -LocalPort 28960 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Call of Duty" -LocalPort 28960 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Perfect World" -LocalPort 29000 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Perfect World" -LocalPort 29000 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Jedi Knight" -LocalPort 29070 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Jedi Knight" -LocalPort 29070 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 29900-29901 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 29900-29901 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 29920 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 29920 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "TetriNET" -LocalPort 31457 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Ace of Spades" -LocalPort 32887 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Infestation: Survivor Stories" -LocalPort 34000 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Factorio" -LocalPort 34197 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Runescape" -LocalPort 43594-43595 -Protocol TCP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Runescape" -LocalPort 43594-43595 -Protocol UDP -Action Block -Enabled True -Direction Inbound +New-NetFirewallRule -DisplayName "Mu Online" -LocalPort 44405 -Protocol TCP -Action Block -Enabled True -Direction Inbound + +New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 20-21 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 22 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 23 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "HTTP" -LocalPort 80 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "TorPark onion routing" -LocalPort 81 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "TorPark control" -LocalPort 82 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "RTelnet" -LocalPort 107 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "RTelnet" -LocalPort 107 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "DHCPv6" -LocalPort 546-547 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "DHCPv6" -LocalPort 546-547 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Flash" -LocalPort 843 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "B.net (Free HK)" -LocalPort 1119 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "B.net (Free HK)" -LocalPort 1119 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Kazaa" -LocalPort 1214 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Kazaa" -LocalPort 1214 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "WASTE" -LocalPort 1337 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Civ" -LocalPort 1492 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Garena" -LocalPort 1513 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Garena" -LocalPort 1513 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "iSketch" -LocalPort 1626-1627 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Defunct RADIUS Ports" -LocalPort 1645-1646 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Windward" -LocalPort 1707 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Windward" -LocalPort 1707 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "America's Army" -LocalPort 1716 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Microsoft Media Services" -LocalPort 1755 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Microsoft Media Services" -LocalPort 1755 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "SSDP" -LocalPort 1900 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Macro Flash" -LocalPort 1935 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Macro Flash" -LocalPort 1935 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Netop" -LocalPort 1970 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Netop" -LocalPort 1970 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Civ 4" -LocalPort 2033 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Civ 4" -LocalPort 2033 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Warzone 2100" -LocalPort 2100 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Apple Notifs" -LocalPort 2195 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Apple Notifs Feedback" -LocalPort 2196 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "ArmA/Halo" -LocalPort 2302-2305 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "AIM/Ghost" -LocalPort 2351-2368 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Ultima Online" -LocalPort 2593 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Ultima Online" -LocalPort 2593 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Ultima Online 2" -LocalPort 2599 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Ultima Online 2" -LocalPort 2599 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "iSync" -LocalPort 3004 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Xbox LIVE" -LocalPort 3074 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Xbox LIVE" -LocalPort 3074 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "iSCSI" -LocalPort 3260 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "iSCSI" -LocalPort 3260 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "RDP" -LocalPort 3389 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "RDP" -LocalPort 3389 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "PlayStation" -LocalPort 3479-3480 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "PlayStation" -LocalPort 3479-3480 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Cyc" -LocalPort 3645 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Cyc" -LocalPort 3645 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BF4" -LocalPort 3659 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Blizzard games/Club Penguin" -LocalPort 3724 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Blizzard games/Club Penguin" -LocalPort 3724 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "WarMUX" -LocalPort 3826 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "WarMUX" -LocalPort 3826 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Warframe" -LocalPort 3960 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Warframe again" -LocalPort 3962 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "OpenTTD" -LocalPort 3978-3979 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "OpenTTD" -LocalPort 3978-3979 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Diablo 2" -LocalPort 4000 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Diablo 2" -LocalPort 4000 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Microsoft Ants" -LocalPort 4001 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Amazon Echo" -LocalPort 4070 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Amazon Echo" -LocalPort 4070 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Microsoft Remote Web Workplace admin" -LocalPort 4125 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Apprentice" -LocalPort 4747 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Many things" -LocalPort 5000 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Many things" -LocalPort 5000 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "LoL" -LocalPort 5000-5500 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Neverwinter Nights" -LocalPort 5121 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Apple Notif 2" -LocalPort 5223 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Outlaws" -LocalPort 5310 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "PostgreSQL" -LocalPort 5432 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Freeciv" -LocalPort 5556 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Freeciv" -LocalPort 5556 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "TeamViewer" -LocalPort 5938 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "TeamViewer" -LocalPort 5938 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "More b.net/CP 2 (Free HK)" -LocalPort 6112 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "More b.net/CP 2 (Free HK)" -LocalPort 6112 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "B.net/Club penguin 3" -LocalPort 6113 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6881-6887 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6881-6887 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6888 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6888 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6889-6900 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6889-6900 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Windows Live Messenger" -LocalPort 6891-6900 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Windows Live Messenger" -LocalPort 6891-6900 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6901 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6901 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6902-6968 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6902-6968 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "BitTorrent tracker" -LocalPort 6969 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "HTTP Bittorrent" -LocalPort 7000 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Enemy Territory: Quake Wars" -LocalPort 7133 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Tibia" -LocalPort 7171 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "WatchMe" -LocalPort 7272 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "WatchMe" -LocalPort 7272 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Rise: The Vieneo Province" -LocalPort 7473 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Saratoga FTP" -LocalPort 7542 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Saratoga FTP" -LocalPort 7542 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 7707-7708 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 7717 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Just Cause 2, Terraria, GTA:SA" -LocalPort 7777 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Just Cause 2, Terraria, GTA:SA" -LocalPort 7777 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Unreal Tournament" -LocalPort 7777-7788 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Unreal Tournament" -LocalPort 7777-7788 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 8075 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "MapleStory" -LocalPort 8484 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "QBittorrent" -LocalPort 9000 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Tor" -LocalPort 9030 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Tor" -LocalPort 9050-9051 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Clash of Clans" -LocalPort 9339 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Club Penguin" -LocalPort 9875 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "CrossFire" -LocalPort 10009 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "CrossFire" -LocalPort 10009 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Touhou" -LocalPort 10080 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Lock On: Modern Air Combat" -LocalPort 10308 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Lock On: Modern Air Combat" -LocalPort 10308 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "SWAT 4" -LocalPort 10480 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "SWAT 4" -LocalPort 10480 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Farming Simulator 2011" -LocalPort 10823 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Savage: Battle for Newerth" -LocalPort 11235 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Savage: Battle for Newerth" -LocalPort 11235 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "OpenRCT2" -LocalPort 11753 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 12012-12013 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 12012-12013 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Second Life" -LocalPort 12035 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Second Life" -LocalPort 12043 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Second Life" -LocalPort 12046 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Cube World" -LocalPort 12345 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Cube World" -LocalPort 12345 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Second Life" -LocalPort 13000-13050 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "CrossFire (again)" -LocalPort 13008 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "CrossFire (again)" -LocalPort 13008 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Battlefield 1942" -LocalPort 14567 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Battlefield Vietnam" -LocalPort 15567 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "XPilot" -LocalPort 15345 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "XPilot" -LocalPort 15345 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Project Zomboid" -LocalPort 16261 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Project Zomboid" -LocalPort 16261 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Battlefield 2" -LocalPort 16567 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Worms" -LocalPort 17011 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Monero P2P" -LocalPort 18080 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18200 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18200 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18201 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18201 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18206 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18206 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18300-18301 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18300-18301 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18306 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18306 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Bitcoin" -LocalPort 18333 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18400-18401 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18400-18401 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18505-18506 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Audition Online Dance Battle" -LocalPort 18505-18506 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "X-BEAT" -LocalPort 18605-18606 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "X-BEAT" -LocalPort 18605-18606 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Minecraft: Bedrock Edition" -LocalPort 19132-19133 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 20560 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 20560 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "0 A.D. Empires Ascendant" -LocalPort 20595 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Duke Nukem 3D" -LocalPort 23513 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Duke Nukem 3D" -LocalPort 23513 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "StepMania: Online: DDR" -LocalPort 24842 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "StepMania: Online: DDR" -LocalPort 24842 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Minecraft" -LocalPort 25565 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Minecraft" -LocalPort 25565 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Minecraft" -LocalPort 25575 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Quake, EVE Online, Xonotic" -LocalPort 26000 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Quake, EVE Online, Xonotic" -LocalPort 26000 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "EVE Online" -LocalPort 26900-26901 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "QuakeWorld" -LocalPort 27000-27006 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27000-27015 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Unturned" -LocalPort 27015-27018 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27015-27030 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27015-27030 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Magicka" -LocalPort 27016 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Magicka" -LocalPort 27016 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27031 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27036-27037 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Steam" -LocalPort 27036-27037 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "QuakeWorld" -LocalPort 27500-27900 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Quake II" -LocalPort 27901-27910 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "OpenArena" -LocalPort 27950 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Enemy Territoy, Quake III, Quake Live" -LocalPort 27960-27969 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Starsiege: Tribes" -LocalPort 28001 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Starsiege: Tribes" -LocalPort 28001 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Rust" -LocalPort 28015 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "AssaultCube Reloaded" -LocalPort 28770-28771 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Cube 2: Sauerbraten" -LocalPort 28785-28786 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 28852 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Killing Floor" -LocalPort 28852 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 28910 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 28910 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Call of Duty" -LocalPort 28960 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Call of Duty" -LocalPort 28960 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Perfect World" -LocalPort 29000 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Perfect World" -LocalPort 29000 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Jedi Knight" -LocalPort 29070 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Jedi Knight" -LocalPort 29070 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 29900-29901 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 29900-29901 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 29920 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Nintendo Wi-Fi" -LocalPort 29920 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "TetriNET" -LocalPort 31457 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Ace of Spades" -LocalPort 32887 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Infestation: Survivor Stories" -LocalPort 34000 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Factorio" -LocalPort 34197 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Runescape" -LocalPort 43594-43595 -Protocol TCP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Runescape" -LocalPort 43594-43595 -Protocol UDP -Action Block -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "Mu Online" -LocalPort 44405 -Protocol TCP -Action Block -Enabled True -Direction Outbound + +#Block multiple protocols with new rule +New-NetFirewallRule -DisplayName "ICMPv4" -Protocol ICMPv4 -Action Block -Enabled True -Direction Inbound -Profile Any +New-NetFirewallRule -DisplayName "ICMPv4" -Protocol ICMPv4 -Action Block -Enabled True -Direction Outbound -Profile Any +New-NetFirewallRule -DisplayName "ICMPv6" -Protocol ICMPv6 -Action Block -Enabled True -Direction Inbound -Profile Any +New-NetFirewallRule -DisplayName "ICMPv6" -Protocol ICMPv6 -Action Block -Enabled True -Direction Outbound -Profile Any + +#Allow multiple ports with new rule +New-NetFirewallRule -DisplayName "HTTPS" -LocalPort 443 -Protocol TCP -Action Allow -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "NTP" -LocalPort 123 -Protocol UDP -Action Allow -Enabled True -Direction Outbound +New-NetFirewallRule -DisplayName "NTP" -LocalPort 123 -Protocol UDP -Action Allow -Enabled True -Direction Inbound + +#Allow multiple features with pre-existing rules +Set-NetFirewallRule -DisplayName "*Defender*" -Enabled True -Action Allow -Profile Any + +} + +Export-ModuleMember -Function set-FirewallRule \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/Firewall/FirewallUp.psm1 b/Scripts/Windows/MasterScriptStuff/Firewall/FirewallUp.psm1 new file mode 100644 index 0000000..03bf68d --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/Firewall/FirewallUp.psm1 @@ -0,0 +1,22 @@ +Function set-Firewall { + #make sure firewall service is running and configurable + Set-Service -name MpsSvc -StartupType Automatic -Status Running + + #Enable the entire firewall + Set-NetFirewallProfile -Name Domain, Public, Private -Enabled True + + #Set direction defaults + Set-NetFirewallProfile -DefaultInboundAction Block -DefaultOutboundAction Allow + + #Settings for profiles + Set-NetFirewallProfile -Name Domain, Private, Public -NotifyOnListen False + + #Unique Settings for Public + Set-NetFirewallProfile -Name Public -AllowLocalFirewallRules False -AllowLocalIPsecRules False + + #Logging for Domain, Private, and Public + Set-NetFirewallProfile -Name Domain, Private, Public -LogFileName %SystemRoot%\System32\LogFiles\Firewall\pfirewall.log -LogMaxSizeKilobytes 16384 -LogBlocked True -LogAllowed True + +} + +Export-ModuleMember -Function set-Firewall \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/Log/Log.psm1 b/Scripts/Windows/MasterScriptStuff/Log/Log.psm1 new file mode 100644 index 0000000..7d5cbdd --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/Log/Log.psm1 @@ -0,0 +1,9 @@ +Function log { + param( + [Parameter(Mandatory=$true)] + [string]$message + ) + Write-Host $message +} + +Export-ModuleMember -Function log \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/MasterScript-Combined.ps1 b/Scripts/Windows/MasterScriptStuff/MasterScript-Combined.ps1 new file mode 100644 index 0000000..e0d4399 --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/MasterScript-Combined.ps1 @@ -0,0 +1,706 @@ +<# +MasterScript-Combined.ps1 +Combined version of MasterScript and its modules. This script inlines the module functions so it can be run as a single file. +Run on Windows PowerShell (run as Administrator). +#> +#region Helpers + +# Command-line switches: use these to run subsets of the script. +param( + [switch]$RunAll, + [switch]$RunFirewall, + [switch]$RunSecPol, + [switch]$RunServices, + [switch]$RunSSH, + [switch]$RunTasks, + [switch]$DisableSAMEnumeration, + [switch]$EnableSAMEnumeration, + [switch]$ScanUsers, + [switch]$SyncUsers, + [string]$UsersSourceUrl = '', + [switch]$WhatIf +) + +#region Helpers +function log { + param( + [Parameter(Mandatory=$true)] + [string]$message + ) + Write-Host $message +} + +function Invoke-Action { + param( + [Parameter(Mandatory=$true)][string]$Description, + [Parameter(Mandatory=$true)][scriptblock]$Action + ) + + if ($WhatIf) { + log "[WhatIf] $Description" + return + } + + try { + log "Starting: $Description" + & $Action + log "Completed: $Description" + } catch { + log "Error during $Description: $_" + } +} + +#endregion + +#region SAM enumeration +function Set-SAMEnumeration { + param( + [Parameter(Mandatory=$true)][bool]$Disable + ) + + $regPath = 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' + $props = @{ + 'RestrictAnonymous' = ($(if ($Disable) {1} else {0})) + 'RestrictAnonymousSAM' = ($(if ($Disable) {1} else {0})) + } + + foreach ($name in $props.Keys) { + $value = $props[$name] + try { + if (Get-ItemProperty -Path $regPath -Name $name -ErrorAction SilentlyContinue) { + Set-ItemProperty -Path $regPath -Name $name -Value $value -ErrorAction Stop + } else { + New-ItemProperty -Path $regPath -Name $name -Value $value -PropertyType DWord -ErrorAction Stop | Out-Null + } + log "Set registry $regPath\$name to $value" + } catch { + log "Failed to set $name in $regPath: $_" + } + } +} +#endregion + +#region Scan user directories for all files +function Scan-UserFiles { + param( + [string]$OutputFile = $(Join-Path -Path ([Environment]::GetFolderPath('Desktop')) -ChildPath 'user_file_paths.txt'), + [string]$ErrorsFile = $(Join-Path -Path ([Environment]::GetFolderPath('Desktop')) -ChildPath 'user_file_paths_errors.txt') + ) + + $roots = @() + if ($IsWindows) { + $roots += 'C:\Users' + } else { + # macOS / Linux + $roots += '/Users' + } + + # Prepare output files + try { Remove-Item -Path $OutputFile -ErrorAction SilentlyContinue } catch { } + try { Remove-Item -Path $ErrorsFile -ErrorAction SilentlyContinue } catch { } + + foreach ($root in $roots) { + if (-not (Test-Path $root)) { + "$root not found" | Out-File -FilePath $ErrorsFile -Encoding utf8 -Append + continue + } + + # Use Get-ChildItem and capture non-terminating errors in $errs + $errs = $null + try { + Get-ChildItem -Path $root -File -Recurse -ErrorAction SilentlyContinue -ErrorVariable errs | ForEach-Object { + $_.FullName + } | Out-File -FilePath $OutputFile -Encoding utf8 -Append + } catch { + "Error scanning $root: $_" | Out-File -FilePath $ErrorsFile -Encoding utf8 -Append + } + + if ($errs) { + $errs | ForEach-Object { + "[$($_.CategoryInfo.Category)] $($_.Exception.Message) --> $($_.CategoryInfo.TargetName)" + } | Out-File -FilePath $ErrorsFile -Encoding utf8 -Append + } + } + + # Report counts + try { + $count = (Get-Content -Path $OutputFile -ErrorAction SilentlyContinue | Measure-Object -Line).Lines + log "Scan complete. Files found: $count. Output: $OutputFile. Errors (if any): $ErrorsFile" + } catch { + log "Scan complete. Output: $OutputFile. Errors (if any): $ErrorsFile" + } +} +#endregion + +#region Sync users from remote source +function Fetch-UserDefinitionsFromUrl { + param( + [Parameter(Mandatory=$true)][string]$Url + ) + + $defs = @{} + try { + log "Fetching user definitions from $Url" + $resp = Invoke-WebRequest -Uri $Url -UseBasicParsing -ErrorAction Stop + $content = $resp.Content -split "`n" + } catch { + log "Failed to fetch $Url: $_" + return $defs + } + + foreach ($line in $content) { + $l = $line.Trim() + if ($l -match '^\|') { + # markdown table row: | username | role | + $parts = $l -split '\|' | ForEach-Object { $_.Trim() } | Where-Object { $_ -ne '' } + if ($parts.Count -ge 2) { + $user = $parts[0] + $role = $parts[1] + if ($user -and $role) { $defs[$user] = $role } + } + continue + } + + # common patterns: "username - admin" or "username: admin" or "- username - admin" + if ($l -match '^[\-\*\+\s]*([A-Za-z0-9_.@\\-]{2,})\s*[:\-]\s*(admin|administrator|localadmin|user|member|standard|non-admin|nonadmin|staff)\b') { + $user = $matches[1] + $role = $matches[2] + $defs[$user] = $role + continue + } + + # lines like "Create user: username (admin)" + if ($l -match '([A-Za-z0-9_.@\\-]{2,})\s*\(?\b(admin|administrator|localadmin)\b\)?') { + $user = $matches[1] + $role = $matches[2] + $defs[$user] = $role + continue + } + } + + # Normalize roles to Admin / User + $normalized = @{} + foreach ($k in $defs.Keys) { + $r = $defs[$k].ToString().ToLower() + if ($r -match 'admin') { $normalized[$k] = 'Admin' } else { $normalized[$k] = 'User' } + } + return $normalized +} + +function Get-AllLocalUsers { + $users = @() + try { + $local = Get-LocalUser -ErrorAction Stop + foreach ($u in $local) { $users += [PSCustomObject]@{ Name = $u.Name; Object = $u } } + return $users + } catch { + # fallback to WinNT ADSI enumeration + try { + $comp = [ADSI]("WinNT://$env:COMPUTERNAME") + foreach ($child in $comp.Children) { + if ($child.SchemaClassName -eq 'User') { + $users += [PSCustomObject]@{ Name = $child.Name; Object = $child } + } + } + } catch { + log "Failed to enumerate local users: $_" + } + } + return $users +} + +function Is-UserInAdminGroup { + param([string]$UserName) + try { + $members = Get-LocalGroupMember -Group 'Administrators' -ErrorAction Stop | Select-Object -ExpandProperty Name + return $members -contains $UserName + } catch { + # fallback: check ADSI + try { + $group = [ADSI]('WinNT://' + $env:COMPUTERNAME + '/Administrators,group') + foreach ($m in $group.Members()) { if ($m.GetType().InvokeMember('Name','GetProperty',$null,$m,$null) -eq $UserName) { return $true } } + } catch { } + } + return $false +} + +function Remove-UserAccount { + param([string]$UserName) + try { Remove-LocalUser -Name $UserName -ErrorAction Stop; log "Removed local user $UserName"; return } catch { } + try { net user $UserName /delete 2>&1 | Out-Null; log "Removed local user $UserName (net user)"; return } catch { log "Failed to remove $UserName: $_" } +} + +function Create-UserAccount { + param( + [string]$UserName, + [string]$Role = 'User' + ) + # generate a random password + $plain = [System.Web.Security.Membership]::GeneratePassword(12,2) -replace '\\','A' + $secure = ConvertTo-SecureString $plain -AsPlainText -Force + try { + New-LocalUser -Name $UserName -Password $secure -FullName $UserName -ErrorAction Stop + log "Created user $UserName" + } catch { + # fallback to net user + try { net user $UserName $plain /add 2>&1 | Out-Null; log "Created user $UserName (net user)" } catch { log "Failed to create $UserName: $_" } + } + + if ($Role -eq 'Admin') { + try { Add-LocalGroupMember -Group 'Administrators' -Member $UserName -ErrorAction Stop; log "Added $UserName to Administrators" } catch { try { net localgroup Administrators $UserName /add 2>&1 | Out-Null; log "Added $UserName to Administrators (net localgroup)" } catch { log "Failed to add $UserName to Administrators: $_" } } + } +} + +function Sync-UsersFromDefinitions { + param([hashtable]$Definitions) + + if ($Definitions.Count -eq 0) { log "No user definitions provided to sync."; return } + + $locals = Get-AllLocalUsers + $localNames = $locals | Select-Object -ExpandProperty Name + $protected = @('Administrator','Guest','DefaultAccount','WDAGUtilityAccount') + $currentUser = $env:USERNAME + + foreach ($lu in $localNames) { + if ($protected -contains $lu) { continue } + if ($lu -eq $currentUser) { continue } + + if (-not $Definitions.ContainsKey($lu)) { + $ans = Read-Host "Local user '$lu' not in remote list. Delete? (y/n)" + if ($ans -match '^[Yy]') { + Invoke-Action "Remove local user $lu" { Remove-UserAccount -UserName $lu } + } else { log "Kept user $lu" } + } else { + # user present in definitions, check admin membership + $expected = $Definitions[$lu] + $isAdmin = Is-UserInAdminGroup -UserName $lu + if ($expected -eq 'Admin' -and -not $isAdmin) { + $ans = Read-Host "User '$lu' should be Admin per source but is not. Add to Administrators? (y/n)" + if ($ans -match '^[Yy]') { Invoke-Action "Add $lu to Administrators" { Add-LocalGroupMember -Group 'Administrators' -Member $lu -ErrorAction SilentlyContinue } } + } elseif ($expected -eq 'User' -and $isAdmin) { + $ans = Read-Host "User '$lu' is Admin but source lists as User. Remove from Administrators? (y/n)" + if ($ans -match '^[Yy]') { Invoke-Action "Remove $lu from Administrators" { Remove-LocalGroupMember -Group 'Administrators' -Member $lu -ErrorAction SilentlyContinue } } + } + } + } + + # Add any missing users listed in definitions + foreach ($k in $Definitions.Keys) { + if (-not ($localNames -contains $k)) { + $role = $Definitions[$k] + $ans = Read-Host "User '$k' (Role=$role) is in remote list but not local. Create? (y/n)" + if ($ans -match '^[Yy]') { + Invoke-Action "Create user $k (Role=$role)" { Create-UserAccount -UserName $k -Role $role } + } else { log "Skipped creating $k" } + } + } +} +#endregion + +#region Firewall functions +function set-FirewallRule { + # Disable every pre-existing rule + Set-NetFirewallRule * -Enabled False -Action NotConfigured + + # Block multiple Windows features by pre-existing rules + Set-NetFirewallRule -DisplayGroup "AllJoyn Router","*BranchCache*","Cast to Device functionality","Connect","Cortana","Delivery Optimization","DIAL protocol server","Feedback Hub","File and Printer Sharing","Get Office","Groove Music","HomeGroup","iSCSI Service","mDNS","Media Center Extenders","Microsoft Edge","Microsoft Photos","Microsoft Solitaire Collection","Movies & TV","MSN Weather","Network Discovery","OneNote","*Wi-Fi*","Paint 3D","Proximity Sharing","*Remote*","Secure Socket Tunneling Protocol","*Skype*","SNMP Trap","Store","*Smart Card*","Virtual Machine Monitoring","Windows Collaboration Computer Name Registration Service","*Windows Media Player*","Windows Peer to Peer Collaboration Foundation","Windows View 3D Preview","*Wireless*","*WFD*","*Xbox*","3D Builder","Captive Portal Flow","Take a Test","Wallet" -Action Block -Enabled True -Profile Any + + # Block multiple insecure protocols by pre-existing rules + Set-NetFirewallRule -DisplayName "*IPv6*","*ICMP*","*SMB*","*UPnP*","*FTP*","*Telnet*" -Action Block -Enabled True -Profile Any + + # Block multiple ports with new rule (Inbound) + New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 20-21 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 22 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 23 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "HTTP" -LocalPort 80 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "TorPark onion routing" -LocalPort 81 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "TorPark control" -LocalPort 82 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "RTelnet" -LocalPort 107 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "RTelnet" -LocalPort 107 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "DHCPv6" -LocalPort 546-547 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "DHCPv6" -LocalPort 546-547 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Flash" -LocalPort 843 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "B.net (Free HK)" -LocalPort 1119 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "B.net (Free HK)" -LocalPort 1119 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Kazaa" -LocalPort 1214 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Kazaa" -LocalPort 1214 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "WASTE" -LocalPort 1337 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Civ" -LocalPort 1492 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Garena" -LocalPort 1513 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Garena" -LocalPort 1513 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "iSketch" -LocalPort 1626-1627 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Defunct RADIUS Ports" -LocalPort 1645-1646 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Windward" -LocalPort 1707 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Windward" -LocalPort 1707 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "America's Army" -LocalPort 1716 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Microsoft Media Services" -LocalPort 1755 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Microsoft Media Services" -LocalPort 1755 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "SSDP" -LocalPort 1900 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Macro Flash" -LocalPort 1935 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Macro Flash" -LocalPort 1935 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Netop" -LocalPort 1970 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Netop" -LocalPort 1970 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Civ 4" -LocalPort 2033 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Civ 4" -LocalPort 2033 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Warzone 2100" -LocalPort 2100 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Apple Notifs" -LocalPort 2195 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Apple Notifs Feedback" -LocalPort 2196 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "ArmA/Halo" -LocalPort 2302-2305 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "AIM/Ghost" -LocalPort 2351-2368 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Ultima Online" -LocalPort 2593 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Ultima Online" -LocalPort 2593 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Ultima Online 2" -LocalPort 2599 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Ultima Online 2" -LocalPort 2599 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "iSync" -LocalPort 3004 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Xbox LIVE" -LocalPort 3074 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Xbox LIVE" -LocalPort 3074 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "iSCSI" -LocalPort 3260 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "iSCSI" -LocalPort 3260 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "RDP" -LocalPort 3389 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "RDP" -LocalPort 3389 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "PlayStation" -LocalPort 3479-3480 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "PlayStation" -LocalPort 3479-3480 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Cyc" -LocalPort 3645 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Cyc" -LocalPort 3645 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "BF4" -LocalPort 3659 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Blizzard games/Club Penguin" -LocalPort 3724 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Blizzard games/Club Penguin" -LocalPort 3724 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "WarMUX" -LocalPort 3826 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "WarMUX" -LocalPort 3826 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Warframe" -LocalPort 3960 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Warframe again" -LocalPort 3962 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "OpenTTD" -LocalPort 3978-3979 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "OpenTTD" -LocalPort 3978-3979 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Diablo 2" -LocalPort 4000 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Diablo 2" -LocalPort 4000 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Microsoft Ants" -LocalPort 4001 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Amazon Echo" -LocalPort 4070 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Amazon Echo" -LocalPort 4070 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Microsoft Remote Web Workplace admin" -LocalPort 4125 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Apprentice" -LocalPort 4747 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Many things" -LocalPort 5000 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Many things" -LocalPort 5000 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "LoL" -LocalPort 5000-5500 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Neverwinter Nights" -LocalPort 5121 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Apple Notif 2" -LocalPort 5223 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Outlaws" -LocalPort 5310 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "PostgreSQL" -LocalPort 5432 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Freeciv" -LocalPort 5556 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Freeciv" -LocalPort 5556 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "TeamViewer" -LocalPort 5938 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "TeamViewer" -LocalPort 5938 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "More b.net/CP 2 (Free HK)" -LocalPort 6112 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "More b.net/CP 2 (Free HK)" -LocalPort 6112 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "B.net/Club penguin 3" -LocalPort 6113 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6881-6887 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6881-6887 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6888 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6888 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6889-6900 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "BitTorrent" -LocalPort 6889-6900 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "BitTorrent tracker" -LocalPort 6969 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "HTTP Bittorrent" -LocalPort 7000 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Enemy Territory: Quake Wars" -LocalPort 7133 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Tibia" -LocalPort 7171 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "WatchMe" -LocalPort 7272 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "WatchMe" -LocalPort 7272 -Protocol UDP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Rise: The Vieneo Province" -LocalPort 7473 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Saratoga FTP" -LocalPort 7542 -Protocol TCP -Action Block -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "Saratoga FTP" -LocalPort 7542 -Protocol UDP -Action Block -Enabled True -Direction Inbound + + # (Outbound rules mirror many of the inbound blocks) + New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 20-21 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 22 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "FTP, SSH, Telnet" -LocalPort 23 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "HTTP" -LocalPort 80 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "TorPark onion routing" -LocalPort 81 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "TorPark control" -LocalPort 82 -Protocol UDP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "RTelnet" -LocalPort 107 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "RTelnet" -LocalPort 107 -Protocol UDP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "DHCPv6" -LocalPort 546-547 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "DHCPv6" -LocalPort 546-547 -Protocol UDP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "Flash" -LocalPort 843 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "B.net (Free HK)" -LocalPort 1119 -Protocol TCP -Action Block -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "B.net (Free HK)" -LocalPort 1119 -Protocol UDP -Action Block -Enabled True -Direction Outbound + + # Block ICMP/ICMPv6 rules + New-NetFirewallRule -DisplayName "ICMPv4" -Protocol ICMPv4 -Action Block -Enabled True -Direction Inbound -Profile Any + New-NetFirewallRule -DisplayName "ICMPv4" -Protocol ICMPv4 -Action Block -Enabled True -Direction Outbound -Profile Any + New-NetFirewallRule -DisplayName "ICMPv6" -Protocol ICMPv6 -Action Block -Enabled True -Direction Inbound -Profile Any + New-NetFirewallRule -DisplayName "ICMPv6" -Protocol ICMPv6 -Action Block -Enabled True -Direction Outbound -Profile Any + + # Allow some necessary outbound ports + New-NetFirewallRule -DisplayName "HTTPS" -LocalPort 443 -Protocol TCP -Action Allow -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "NTP" -LocalPort 123 -Protocol UDP -Action Allow -Enabled True -Direction Outbound + New-NetFirewallRule -DisplayName "NTP" -LocalPort 123 -Protocol UDP -Action Allow -Enabled True -Direction Inbound + + # Allow Defender related rules + Set-NetFirewallRule -DisplayName "*Defender*" -Enabled True -Action Allow -Profile Any +} + +function set-Firewall { + # Ensure firewall service running + Set-Service -Name MpsSvc -StartupType Automatic -Status Running + + # Enable the firewall profiles + Set-NetFirewallProfile -Name Domain, Public, Private -Enabled True + + # Set direction defaults + Set-NetFirewallProfile -DefaultInboundAction Block -DefaultOutboundAction Allow + + # Settings for profiles + Set-NetFirewallProfile -Name Domain, Private, Public -NotifyOnListen False + + # Unique settings for Public + Set-NetFirewallProfile -Name Public -AllowLocalFirewallRules False -AllowLocalIPsecRules False + + # Logging settings + Set-NetFirewallProfile -Name Domain, Private, Public -LogFileName "$env:SystemRoot\System32\LogFiles\Firewall\pfirewall.log" -LogMaxSizeKilobytes 16384 -LogBlocked True -LogAllowed True +} +#endregion + +#region SSH +function setSSHconfig { + # Start the service and ensure startup + Set-Service -Name sshd -StartupType Automatic -Status Running + + # Configure firewall rules for SSH (ensure idempotency) + # Remove any previous blocking rule on port 22 (if present) + Get-NetFirewallRule -ErrorAction SilentlyContinue | Where-Object { ($_ | Get-NetFirewallPortFilter -ErrorAction SilentlyContinue).LocalPort -contains 22 } | Remove-NetFirewallRule -ErrorAction SilentlyContinue + + New-NetFirewallRule -DisplayName "OpenSSH" -Protocol TCP -LocalPort 22 -Action Allow -Enabled True -Direction Inbound + New-NetFirewallRule -DisplayName "OpenSSH" -Protocol TCP -LocalPort 22 -Action Allow -Enabled True -Direction Outbound +} +#endregion + +#region SecPol helpers +function Get-Secpol { + param( + [Parameter(Mandatory=$true)] + [string]$CfgFile + ) + secedit /export /cfg "$CfgFile" | Out-Null + $obj = New-Object psobject + $index = 0 + $contents = Get-Content $CfgFile -Raw + [regex]::Matches($contents,"(?<=\[)(.*)(?=\])") | ForEach-Object { + $title = $_.Value + [regex]::Matches($contents,"(?<=\]).*?((?=\[)|(\Z))", [System.Text.RegularExpressions.RegexOptions]::Singleline)[$index] | ForEach-Object{ + $section = New-Object psobject + $_.Value -split "\r\n" | Where-Object{$_.Length -gt 0} | ForEach-Object { + $value = [regex]::Match($_,"(?<=\=).*).Value + $name = [regex]::Match($_,".*(?=\=") ).Value + } + } + $index += 1 + } + + # Fallback simple parser (previous implementation returned a nested PSObject). + # Use the original implementation from module file for compatibility instead of complex rewrite. + secedit /export /cfg "$CfgFile" | Out-Null + $obj = New-Object psobject + $index = 0 + $contents = Get-Content $CfgFile -Raw + [regex]::Matches($contents,"(?<=\[)(.*)(?=\])") | ForEach-Object { + $title = $_ + [regex]::Matches($contents,"(?<=\]).*?((?=\[)|())", [System.Text.RegularExpressions.RegexOptions]::Singleline)[$index] | ForEach-Object{ + $section = New-Object psobject + $_.Value -split "\r\n" | Where-Object{ $_.Length -gt 0 } | ForEach-Object { + $value = [regex]::Match($_,"(?<=\=).*" ).Value + $name = [regex]::Match($_,".*(?=\=)" ).Value + try { $section | Add-Member -MemberType NoteProperty -Name $name.ToString().Trim() -Value $value.ToString().Trim() -ErrorAction SilentlyContinue } catch { } + } + try { $obj | Add-Member -MemberType NoteProperty -Name $title -Value $section } catch { } + } + $index += 1 + } + return $obj +} + +function Set-SecPol { + param( + [Parameter(Mandatory=$true)] + $Object, + [Parameter(Mandatory=$true)] + [string]$CfgFile + ) + $Object.psobject.Properties.GetEnumerator() | ForEach-Object{ + "[$($_.Name)]" + $_.Value | ForEach-Object{ + $_.psobject.Properties.GetEnumerator() | ForEach-Object{ + "$($_.Name)=$($_.Value)" + } + } + } | Out-File -FilePath $CfgFile -ErrorAction Stop -Encoding ASCII + secedit /configure /db c:\windows\security\local.sdb /cfg "$CfgFile" /areas SECURITYPOLICY +} +#endregion + +#region Services and Tasks +function disableUnsecureServices { + # Disable unneeded/insecure services (idempotent) + $svcnames = @( + 'Browser','bthserv','Fax','icssvc','irmon','lfsvc','lltdsvc','MapsBroker','MSiSCSI','p2pimsvc','p2psvc','PhoneSvc','PlugPlay','PNRPAutoReg','PNRPsvc','RasAuto','RemoteAccess','RemoteRegistry','RpcLocator','SessionEnv','SharedAccess','SNMPTRAP','SSDPSRV','TermService','UmRdpService','upnphost','vmicrdv','W32Time','W3SVC','wercplsupport','WerSvc','WinHttpAutoProxySvc','WinRM','WlanSvc','WMPNetworkSvc','WpnService','WpnUserService*','WwanSvc','xbgm','XblAuthManager','XblGameSave','XboxGipSvc','XboxNetApiSvc','PushToInstall','spectrum','icssvc','wisvc','StiSvc','FrameServer','WbioSrvc','WFDSConSvc','WebClient','WMSVC','WalletService','UevAgentService','UwfServcingSvc','TabletInputService','TapiSrv','WiaRpc','SharedRealitySvc','SNMP','SCPolicySvc','ScDeviceEnum','simptcp','ShellHWDetection','shpamsvc','SensorService','SensrSvc','SensorDataService','SstpSvc','iprip','RetailDemo','RasMan','RmSvc','PrintNotify','WpcMonSvc','SEMgrSvc','CscService','NcaSVC','NcbService','NcdAutoSetup','Netlogon','NetTcpPortSharing','NetTcpActivator','NetMsmqActivator','Wms','WmsRepair','SmsRouter','MsKeyboardFilter','ftpsvc','AppVClient','wlidsvc','diagnosticshub.standardcollector.service','MSMQTriggers','MSMQ','LxssManager','LPDSVC','lpxlatCfgSvc','iphlpsvc','IISADMIN','vmicvss','vmms','vmictimesync','vmicrdv','vmicmsession','vmcompute','vmicheartbeat','vmicshutdown','vmicguestinterface','vmickvpexchange','HvHost','EapHost','dmwappushsvc','TrkWks','WdiSystemHost','WdiServiceHost','diagsvc','DiagTrack','NfsClnt','CertPropSvc','CaptureService_*','camsvc','PeerDistSvc','BluetoothUserService_*','BTAGService','BthAvctpSvc','tzautoupdate','ALG','AJRouter' + ) + foreach ($s in $svcnames) { + try { + Set-Service -Status Stopped -StartupType Disabled -Name $s -ErrorAction SilentlyContinue + } catch { } + } + + # Enable needed services + $needed = @('BDESVC','BFE','CryptSvc','DcomLaunch','Dhcp','Dnscache','EventLog','Group','LanmanServer','LanmanWorkstation','MpsSvc','nsi','Power','RpcEptMapper','RpcSs','SamSs','SecurityHealthService','Sense','WdNisSvc','Wecsvc','WEPHOSTSVC','WinDefend','wuauserv','WSearch','TrustedInstaller','Winmgmt','msiserver','FontCache','Wcmsvc','AudioSrv','AudioEndpointBuilder','vds','ProfSvc','UserManager','UsoSvc','Themes','Schedule','SgrmBroker','SystemEventsBroker','SENS','OneSyncSvc_*','SysMain','sppsvc','wscsvc','PcaSvc','Spooler','WPDBusEnum','ssh-agent','NlaSvc','LSM','gpsvc','EFS','DPS','DoSvc','DusmSvc','CoreMessagingRegistrar','CDPUserSvc_*','CDPSvc','EventSystem','BrokerInfrastructure','BITS','AppHostSvc') + foreach ($n in $needed) { + try { Set-Service -Status Running -StartupType Automatic -Name $n -ErrorAction SilentlyContinue } catch { } + } + + # Manual services list + $manual = @('dot3svc','WaaSMedicSvc','wmiApSrv','LicenseManager','SDRSVC','TokenBroker','W3LOGSVC','VSS','UnistoreSvc_*','UserDataSvc_*','upnphost','TimeBroker','lmhosts','TieringEngineService','StorSvc','StateRepository','svsvc','seclogon','QWAVE','PrintWorkflowUserSvc_*','pla','PerfHost','defragsvc','NetSetupSvc','netprofm','Netman','InstallService','smphost','sqprv','NgcCtnrSvc','NgcSvc','MessagingService_*','wlpasvc','KtmRm','UI0Detect','PolicyAgent','IKEEXT','hidserv','hns','GraphicsPerfSvc','FDResPub','fdPHost','fhsvc','EntAppSvc','embeddedmode','DsRoleSvc','MSDTC','DevQueryBroker','DevicesFlowUserSvc_*','DevicePickerUserSvc_*','DsmSVC','DmEnrollmentSvc','DeviceInstall','DsSvc','COMSysApp','KeyIso','ClipSVC','c2wts','wbegine','aspnet_state','AssignedAccessManagerSvc','AppXSVC','AppMgmt','Appinfo','AppIDSvc','AppReadiness','AxInstSV') + foreach ($m in $manual) { + try { Set-Service -StartupType Manual -Name $m -ErrorAction SilentlyContinue } catch { } + } + + # Some services cannot be disabled but should be stopped or set manual + $stoppedManual = @('BcastDVRUserService_*','DeviceAssociationService','VaultSvc','PimIndexMaintenanceSvc_*') + foreach ($t in $stoppedManual) { + try { Set-Service -Status Stopped -StartupType Manual -Name $t -ErrorAction SilentlyContinue } catch { } + } +} + +function disableTasks { + try { Unregister-ScheduledTask -TaskPath *Bluetooth* -ErrorAction SilentlyContinue } catch { } + try { Unregister-ScheduledTask -TaskPath *Location* -ErrorAction SilentlyContinue } catch { } + try { Unregister-ScheduledTask -TaskPath *Maps* -ErrorAction SilentlyContinue } catch { } + try { Unregister-ScheduledTask -TaskPath *UPnP* -ErrorAction SilentlyContinue } catch { } + try { Unregister-ScheduledTask -TaskPath '*Plug and Play*' -ErrorAction SilentlyContinue } catch { } + try { Unregister-ScheduledTask -TaskPath '*Windows Error Reporting*' -ErrorAction SilentlyContinue } catch { } +} +#endregion + +# Main orchestration (selective by switches) +try { + $ScriptDir = Split-Path -Parent $MyInvocation.MyCommand.Definition + log "Using script dir: $ScriptDir" + + $systemAccessPath = Join-Path $ScriptDir 'lib/System Access.json' + $eventAuditPath = Join-Path $ScriptDir 'lib/Event Audit.json' + + if (Test-Path $systemAccessPath) { + $SystemAccessSecPolConfig = Get-Content -Path $systemAccessPath | ConvertFrom-Json + } else { log "Warning: $systemAccessPath not found"; $SystemAccessSecPolConfig = $null } + + if (Test-Path $eventAuditPath) { + $EventAuditSecPolConfig = Get-Content -Path $eventAuditPath | ConvertFrom-Json + } else { log "Warning: $eventAuditPath not found"; $EventAuditSecPolConfig = $null } + + $secTemp = Join-Path $env:TEMP 'SecPool.cfg' + + # Determine which actions to run + $DoFirewall = $RunAll -or $RunFirewall + $DoSecPol = $RunAll -or $RunSecPol + $DoServices = $RunAll -or $RunServices + $DoSSH = $RunAll -or $RunSSH + $DoTasks = $RunAll -or $RunTasks + # Default secure behavior: when -RunAll is used, disable SAM enumeration unless explicitly enabled + $DoSAMDisable = $DisableSAMEnumeration -or $RunAll + $DoSAMEnable = $EnableSAMEnumeration + + if ($DoSecPol) { + Invoke-Action "Export current SecPol and apply JSON settings" { + log "Exporting current SecPol to $secTemp" + $SecPool = Get-Secpol -CfgFile $secTemp + + if ($SystemAccessSecPolConfig -ne $null) { + $SystemAccessSecPolConfig.PSObject.Properties | ForEach-Object { + $name = $_.Name + $value = $_.Value + + if (-not $SecPool.PSObject.Properties.Match('System Access')) { + $null = $SecPool | Add-Member -MemberType NoteProperty -Name 'System Access' -Value (New-Object PSObject) -Force + } + try { $SecPool.'System Access'.$name = $value } catch { } + } + } + + if ($EventAuditSecPolConfig -ne $null) { + $EventAuditSecPolConfig.PSObject.Properties | ForEach-Object { + $name = $_.Name + $value = $_.Value + + if (-not $SecPool.PSObject.Properties.Match('Event Audit')) { + $null = $SecPool | Add-Member -MemberType NoteProperty -Name 'Event Audit' -Value (New-Object PSObject) -Force + } + try { $SecPool.'Event Audit'.$name = $value } catch { } + } + } + + Set-SecPol -Object $SecPool -CfgFile $secTemp + } + } + + if ($DoFirewall) { + Invoke-Action "Configure firewall rules" { + set-FirewallRule + set-Firewall + } + } + + if ($DoTasks) { + Invoke-Action "Disable scheduled tasks" { + disableTasks + } + } + + if ($DoServices) { + Invoke-Action "Disable insecure services" { + disableUnsecureServices + } + } + + if ($DoSSH) { + Invoke-Action "Configure SSH" { + setSSHconfig + } + } + + if ($DoSAMDisable -and $DoSAMEnable) { + log "Cannot specify both -DisableSAMEnumeration and -EnableSAMEnumeration. Choose one." + } elseif ($DoSAMDisable) { + Invoke-Action "Disable anonymous enumeration of SAM accounts and shares" { + Set-SAMEnumeration -Disable $true + } + } elseif ($DoSAMEnable) { + Invoke-Action "Enable anonymous enumeration of SAM accounts and shares" { + Set-SAMEnumeration -Disable $false + } + } + + if ($ScanUsers) { + Invoke-Action "Scan user directories for all files and save to Desktop" { + Scan-UserFiles + } + } + + if ($SyncUsers) { + $url = $UsersSourceUrl + if ([string]::IsNullOrWhiteSpace($url)) { + $url = Read-Host "Enter the URL of the CyberPatriot README or user list to sync from" + } + if (-not [string]::IsNullOrWhiteSpace($url)) { + $defs = Fetch-UserDefinitionsFromUrl -Url $url + if ($defs.Count -gt 0) { + Sync-UsersFromDefinitions -Definitions $defs + } else { log "No user definitions parsed from $url" } + } else { log "No URL provided for user sync." } + } + + if (-not ($DoSecPol -or $DoFirewall -or $DoTasks -or $DoServices -or $DoSSH)) { + log "No action switches provided. Use -RunAll or one of -RunFirewall, -RunSecPol, -RunServices, -RunSSH, -RunTasks. Use -WhatIf for a dry-run." + } else { + log "Completed selected actions." + } + +} catch { + log "Error during execution: $_" + throw +} diff --git a/Scripts/Windows/MasterScriptStuff/MasterScript.ps1 b/Scripts/Windows/MasterScriptStuff/MasterScript.ps1 new file mode 100644 index 0000000..0ae6306 --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/MasterScript.ps1 @@ -0,0 +1,50 @@ +# SECPOL +Import-Module .\src\secpol\Get-Secpol +Import-Module .\src\secpol\Set-Secpol + +$SystemAccessSecPolConfig = Get-Content -Path '.\lib\secpol\System Access.json' | ConvertFrom-Json +$EventAuditSecPolConfig = Get-Content -Path '.\lib\secpol\Event Audit.json' | ConvertFrom-Json + +# basic modules +Import-Module .\src\modules\log + +# firewall modules +Import-Module '.\src\Firewalls\Firewall Rules.psm1' +Import-Module '.\src\Firewalls\firewall.psm1' + +#Tasks +Import-Module .\src\tasks\tasks.psm1 + +# unsecure services +Import-Module .\src\services\services.psm1 + +# SSH +Import-Module .\src\SSH\sshconf.psm1 +# SECPOL (System Access) +$SecPool = Get-Secpol "C:\Windows\Temp\SecPool.cfg" + + +$SystemAccessSecPolConfig.PSObject.Properties | ForEach-Object { + $name = $_.Name + $value = $_.Value + + $SecPool.'System Access'.$name = $value +} + +$EventAuditSecPolConfig.PSObject.Properties | ForEach-Object { + $name = $_.Name + $value = $_.Value + + $SecPool.'Event Audit'.$name = $value +} + +Set-SecPol -Object $SecPool -CfgFile "C:\Windows\Temp\SecPool.cfg" + +set-FirewallRule; +set-Firewall; + +disableTasks; + +disableUnsecureServices; + +setSSHconfig; \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/SSH/SSHConf.psm1 b/Scripts/Windows/MasterScriptStuff/SSH/SSHConf.psm1 new file mode 100644 index 0000000..c79ca37 --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/SSH/SSHConf.psm1 @@ -0,0 +1,12 @@ +Function setSSHconfig { + #Start the service + Set-Service -Name sshd -StartupType Automatic -Status Running + + #Config firewall services to allow + Set-NetFireWallRule -LocalPort 22 -Enabled False + New-NetFireWallRule -DisplayName "OpenSSH" -Protocol TCP -LocalPort 22 -Action Allow -Enabled True -Direction Inbound + New-NetFireWallRule -DisplayName "OpenSSH" -Protocol TCP -LocalPort 22 -Action Allow -Enabled True -Direction Outbound + +} + +Export-ModuleMember -Function setSSHconfig \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/SecPol/GetSecPol.psm1 b/Scripts/Windows/MasterScriptStuff/SecPol/GetSecPol.psm1 new file mode 100644 index 0000000..8d55bb0 --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/SecPol/GetSecPol.psm1 @@ -0,0 +1,24 @@ +Function Get-Secpol($CfgFile){ + secedit /export /cfg "$CfgFile" | out-null + $obj = New-Object psobject + $index = 0 + $contents = Get-Content $CfgFile -raw + [regex]::Matches($contents,"(?<=\[)(.*)(?=\])") | ForEach-Object { + $title = $_ + [regex]::Matches($contents,"(?<=\]).*?((?=\[)|(\Z))", [System.Text.RegularExpressions.RegexOptions]::Singleline)[$index] | ForEach-Object{ + $section = new-object psobject + $_.value -split "\r\n" | Where-Object{$_.length -gt 0} | ForEach-Object { + $value = [regex]::Match($_,"(?<=\=).*").value + $name = [regex]::Match($_,".*(?=\=)").value + $section | add-member -MemberType NoteProperty -Name $name.tostring().trim() -Value $value.tostring().trim() -ErrorAction SilentlyContinue | out-null + } + $obj | Add-Member -MemberType NoteProperty -Name $title -Value $section + } + $index += 1 + } + return $obj +} + + + +Export-ModuleMember -Function Get-Secpol \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/SecPol/SetSecPol.psm1 b/Scripts/Windows/MasterScriptStuff/SecPol/SetSecPol.psm1 new file mode 100644 index 0000000..78c7b58 --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/SecPol/SetSecPol.psm1 @@ -0,0 +1,13 @@ +Function Set-SecPol($Object, $CfgFile){ + $SecPool.psobject.Properties.GetEnumerator() | ForEach-Object{ + "[$($_.Name)]" + $_.Value | ForEach-Object{ + $_.psobject.Properties.GetEnumerator() | ForEach-Object{ + "$($_.Name)=$($_.Value)" + } + } + } | out-file $CfgFile -ErrorAction Stop + secedit /configure /db c:\windows\security\local.sdb /cfg "$CfgFile" /areas SECURITYPOLICY + } + + Export-ModuleMember -Function Set-SecPol \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/Services/SetServices.psm1 b/Scripts/Windows/MasterScriptStuff/Services/SetServices.psm1 new file mode 100644 index 0000000..d94a34e --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/Services/SetServices.psm1 @@ -0,0 +1,276 @@ +Function disableUnsecureServices { + #Disable unneeded/insecure services + Set-Service -Status Stopped -StartupType Disabled -Name Browser + Set-Service -Status Stopped -StartupType Disabled -Name bthserv + Set-Service -Status Stopped -StartupType Disabled -Name Fax + Set-Service -Status Stopped -StartupType Disabled -Name icssvc + Set-Service -Status Stopped -StartupType Disabled -Name irmon + Set-Service -Status Stopped -StartupType Disabled -Name lfsvc + Set-Service -Status Stopped -StartupType Disabled -Name lltdsvc + Set-Service -Status Stopped -StartupType Disabled -Name MapsBroker + Set-Service -Status Stopped -StartupType Disabled -Name MSiSCSI + Set-Service -Status Stopped -StartupType Disabled -Name p2pimsvc + Set-Service -Status Stopped -StartupType Disabled -Name p2psvc + Set-Service -Status Stopped -StartupType Disabled -Name PhoneSvc + Set-Service -Status Stopped -StartupType Disabled -Name PlugPlay + Set-Service -Status Stopped -StartupType Disabled -Name PNRPAutoReg + Set-Service -Status Stopped -StartupType Disabled -Name PNRPsvc + Set-Service -Status Stopped -StartupType Disabled -Name RasAuto + Set-Service -Status Stopped -StartupType Disabled -Name RemoteAccess + Set-Service -Status Stopped -StartupType Disabled -Name RemoteRegistry + Set-Service -Status Stopped -StartupType Disabled -Name RpcLocator + Set-Service -Status Stopped -StartupType Disabled -Name SessionEnv + Set-Service -Status Stopped -StartupType Disabled -Name SharedAccess + Set-Service -Status Stopped -StartupType Disabled -Name SNMPTRAP + Set-Service -Status Stopped -StartupType Disabled -Name SSDPSRV + Set-Service -Status Stopped -StartupType Disabled -Name TermService + Set-Service -Status Stopped -StartupType Disabled -Name UmRdpService + Set-Service -Status Stopped -StartupType Disabled -Name upnphost + Set-Service -Status Stopped -StartupType Disabled -Name vmicrdv + Set-Service -Status Stopped -StartupType Disabled -Name W32Time + Set-Service -Status Stopped -StartupType Disabled -Name W3SVC + Set-Service -Status Stopped -StartupType Disabled -Name wercplsupport + Set-Service -Status Stopped -StartupType Disabled -Name WerSvc + Set-Service -Status Stopped -StartupType Disabled -Name WinHttpAutoProxySvc + Set-Service -Status Stopped -StartupType Disabled -Name WinRM + Set-Service -Status Stopped -StartupType Disabled -Name WlanSvc + Set-Service -Status Stopped -StartupType Disabled -Name WMPNetworkSvc + Set-Service -Status Stopped -StartupType Disabled -Name WpnService + Set-Service -Status Stopped -StartupType Disabled -Name WpnUserService* + Set-Service -Status Stopped -StartupType Disabled -Name WwanSvc + Set-Service -Status Stopped -StartupType Disabled -Name xbgm + Set-Service -Status Stopped -StartupType Disabled -Name XblAuthManager + Set-Service -Status Stopped -StartupType Disabled -Name XblGameSave + Set-Service -Status Stopped -StartupType Disabled -Name XboxGipSvc + Set-Service -Status Stopped -StartupType Disabled -Name XboxNetApiSvc + Set-Service -Status Stopped -StartupType Disabled -Name PushToInstall + Set-Service -Status Stopped -StartupType Disabled -Name spectrum + Set-Service -Status Stopped -StartupType Disabled -Name icssvc + Set-Service -Status Stopped -StartupType Disabled -Name wisvc + Set-Service -Status Stopped -StartupType Disabled -Name StiSvc + Set-Service -Status Stopped -StartupType Disabled -Name FrameServer + Set-Service -Status Stopped -StartupType Disabled -Name WbioSrvc + Set-Service -Status Stopped -StartupType Disabled -Name WFDSConSvc + Set-Service -Status Stopped -StartupType Disabled -Name WebClient + Set-Service -Status Stopped -StartupType Disabled -Name WMSVC + Set-Service -Status Stopped -StartupType Disabled -Name WalletService + Set-Service -Status Stopped -StartupType Disabled -Name UevAgentService + Set-Service -Status Stopped -StartupType Disabled -Name UwfServcingSvc + Set-Service -Status Stopped -StartupType Disabled -Name TabletInputService + Set-Service -Status Stopped -StartupType Disabled -Name TapiSrv + Set-Service -Status Stopped -StartupType Disabled -Name WiaRpc + Set-Service -Status Stopped -StartupType Disabled -Name SharedRealitySvc + Set-Service -Status Stopped -StartupType Disabled -Name SNMP + Set-Service -Status Stopped -StartupType Disabled -Name SCPolicySvc + Set-Service -Status Stopped -StartupType Disabled -Name ScDeviceEnum + Set-Service -Status Stopped -StartupType Disabled -Name simptcp + Set-Service -Status Stopped -StartupType Disabled -Name ShellHWDetection + Set-Service -Status Stopped -StartupType Disabled -Name shpamsvc + Set-Service -Status Stopped -StartupType Disabled -Name SensorService + Set-Service -Status Stopped -StartupType Disabled -Name SensrSvc + Set-Service -Status Stopped -StartupType Disabled -Name SensorDataService + Set-Service -Status Stopped -StartupType Disabled -Name SstpSvc + Set-Service -Status Stopped -StartupType Disabled -Name iprip + Set-Service -Status Stopped -StartupType Disabled -Name RetailDemo + Set-Service -Status Stopped -StartupType Disabled -Name RasMan + Set-Service -Status Stopped -StartupType Disabled -Name RmSvc + Set-Service -Status Stopped -StartupType Disabled -Name PrintNotify + Set-Service -Status Stopped -StartupType Disabled -Name WpcMonSvc + Set-Service -Status Stopped -StartupType Disabled -Name SEMgrSvc + Set-Service -Status Stopped -StartupType Disabled -Name CscService + Set-Service -Status Stopped -StartupType Disabled -Name NcaSVC + Set-Service -Status Stopped -StartupType Disabled -Name NcbService + Set-Service -Status Stopped -StartupType Disabled -Name NcdAutoSetup + Set-Service -Status Stopped -StartupType Disabled -Name Netlogon + Set-Service -Status Stopped -StartupType Disabled -Name NetTcpPortSharing + Set-Service -Status Stopped -StartupType Disabled -Name NetTcpActivator + Set-Service -Status Stopped -StartupType Disabled -Name NetMsmqActivator + Set-Service -Status Stopped -StartupType Disabled -Name Wms + Set-Service -Status Stopped -StartupType Disabled -Name WmsRepair + Set-Service -Status Stopped -StartupType Disabled -Name SmsRouter + Set-Service -Status Stopped -StartupType Disabled -Name MsKeyboardFilter + Set-Service -Status Stopped -StartupType Disabled -Name ftpsvc + Set-Service -Status Stopped -StartupType Disabled -Name AppVClient + Set-Service -Status Stopped -StartupType Disabled -Name wlidsvc + Set-Service -Status Stopped -StartupType Disabled -Name diagnosticshub.standardcollector.service + Set-Service -Status Stopped -StartupType Disabled -Name MSMQTriggers + Set-Service -Status Stopped -StartupType Disabled -Name MSMQ + Set-Service -Status Stopped -StartupType Disabled -Name LxssManager + Set-Service -Status Stopped -StartupType Disabled -Name LPDSVC + Set-Service -Status Stopped -StartupType Disabled -Name lpxlatCfgSvc + Set-Service -Status Stopped -StartupType Disabled -Name iphlpsvc + Set-Service -Status Stopped -StartupType Disabled -Name IISADMIN + Set-Service -Status Stopped -StartupType Disabled -Name vmicvss + Set-Service -Status Stopped -StartupType Disabled -Name vmms + Set-Service -Status Stopped -StartupType Disabled -Name vmictimesync + Set-Service -Status Stopped -StartupType Disabled -Name vmicrdv + Set-Service -Status Stopped -StartupType Disabled -Name vmicmsession + Set-Service -Status Stopped -StartupType Disabled -Name vmcompute + Set-Service -Status Stopped -StartupType Disabled -Name vmicheartbeat + Set-Service -Status Stopped -StartupType Disabled -Name vmicshutdown + Set-Service -Status Stopped -StartupType Disabled -Name vmicguestinterface + Set-Service -Status Stopped -StartupType Disabled -Name vmickvpexchange + Set-Service -Status Stopped -StartupType Disabled -Name HvHost + Set-Service -Status Stopped -StartupType Disabled -Name EapHost + Set-Service -Status Stopped -StartupType Disabled -Name dmwappushsvc + Set-Service -Status Stopped -StartupType Disabled -Name TrkWks + Set-Service -Status Stopped -StartupType Disabled -Name WdiSystemHost + Set-Service -Status Stopped -StartupType Disabled -Name WdiServiceHost + Set-Service -Status Stopped -StartupType Disabled -Name diagsvc + Set-Service -Status Stopped -StartupType Disabled -Name DiagTrack + Set-Service -Status Stopped -StartupType Disabled -Name NfsClnt + Set-Service -Status Stopped -StartupType Disabled -Name CertPropSvc + Set-Service -Status Stopped -StartupType Disabled -Name CaptureService_* + Set-Service -Status Stopped -StartupType Disabled -Name camsvc + Set-Service -Status Stopped -StartupType Disabled -Name PeerDistSvc + Set-Service -Status Stopped -StartupType Disabled -Name BluetoothUserService_* + Set-Service -Status Stopped -StartupType Disabled -Name BTAGService + Set-Service -Status Stopped -StartupType Disabled -Name BthAvctpSvc + Set-Service -Status Stopped -StartupType Disabled -Name tzautoupdate + Set-Service -Status Stopped -StartupType Disabled -Name ALG + Set-Service -Status Stopped -StartupType Disabled -Name AJRouter + + #Enable needed services + Set-Service -Status Running -StartupType Automatic -Name BDESVC + Set-Service -Status Running -StartupType Automatic -Name BFE + Set-Service -Status Running -StartupType Automatic -Name CryptSvc + Set-Service -Status Running -StartupType Automatic -Name DcomLaunch + Set-Service -Status Running -StartupType Automatic -Name Dhcp + Set-Service -Status Running -StartupType Automatic -Name Dnscache + Set-Service -Status Running -StartupType Automatic -Name EventLog + Set-Service -Status Running -StartupType Automatic -Name Group + Set-Service -Status Running -StartupType Automatic -Name LanmanServer + Set-Service -Status Running -StartupType Automatic -Name LanmanWorkstation + Set-Service -Status Running -StartupType Automatic -Name MpsSvc + Set-Service -Status Running -StartupType Automatic -Name nsi + Set-Service -Status Running -StartupType Automatic -Name Power + Set-Service -Status Running -StartupType Automatic -Name RpcEptMapper + Set-Service -Status Running -StartupType Automatic -Name RpcSs + Set-Service -Status Running -StartupType Automatic -Name SamSs + Set-Service -Status Running -StartupType Automatic -Name SecurityHealthService + Set-Service -Status Running -StartupType Automatic -Name Sense + Set-Service -Status Running -StartupType Automatic -Name WdNisSvc + Set-Service -Status Running -StartupType Automatic -Name Wecsvc + Set-Service -Status Running -StartupType Automatic -Name WEPHOSTSVC + Set-Service -Status Running -StartupType Automatic -Name WinDefend + Set-Service -Status Running -StartupType Automatic -Name wuauserv + Set-Service -Status Running -StartupType Automatic -Name WSearch + Set-Service -Status Running -StartupType Automatic -Name TrustedInstaller + Set-Service -Status Running -StartupType Automatic -Name Winmgmt + Set-Service -Status Running -StartupType Automatic -Name msiserver + Set-Service -Status Running -StartupType Automatic -Name FontCache + Set-Service -Status Running -StartupType Automatic -Name Wecsvc + Set-Service -Status Running -StartupType Automatic -Name Wcmsvc + Set-Service -Status Running -StartupType Automatic -Name AudioSrv + Set-Service -Status Running -StartupType Automatic -Name AudioEndpointBuilder + Set-Service -Status Running -StartupType Automatic -Name vds + Set-Service -Status Running -StartupType Automatic -Name ProfSvc + Set-Service -Status Running -StartupType Automatic -Name UserManager + Set-Service -Status Running -StartupType Automatic -Name UsoSvc + Set-Service -Status Running -StartupType Automatic -Name Themes + Set-Service -Status Running -StartupType Automatic -Name Schedule + Set-Service -Status Running -StartupType Automatic -Name SgrmBroker + Set-Service -Status Running -StartupType Automatic -Name SystemEventsBroker + Set-Service -Status Running -StartupType Automatic -Name SENS + Set-Service -Status Running -StartupType Automatic -Name OneSyncSvc_* + Set-Service -Status Running -StartupType Automatic -Name SysMain + Set-Service -Status Running -StartupType Automatic -Name sppsvc + Set-Service -Status Running -StartupType Automatic -Name wscsvc + Set-Service -Status Running -StartupType Automatic -Name PcaSvc + Set-Service -Status Running -StartupType Automatic -Name Spooler + Set-Service -Status Running -StartupType Automatic -Name WPDBusEnum + Set-Service -Status Running -StartupType Automatic -Name ssh-agent + Set-Service -Status Running -StartupType Automatic -Name NlaSvc + Set-Service -Status Running -StartupType Automatic -Name LSM + Set-Service -Status Running -StartupType Automatic -Name gpsvc + Set-Service -Status Running -StartupType Automatic -Name EFS + Set-Service -Status Running -StartupType Automatic -Name DPS + Set-Service -Status Running -StartupType Automatic -Name DoSvc + Set-Service -Status Running -StartupType Automatic -Name DcomLaunch + Set-Service -Status Running -StartupType Automatic -Name DusmSvc + Set-Service -Status Running -StartupType Automatic -Name CoreMessagingRegistrar + Set-Service -Status Running -StartupType Automatic -Name CDPUserSvc_* + Set-Service -Status Running -StartupType Automatic -Name CDPSvc + Set-Service -Status Running -StartupType Automatic -Name EventSystem + Set-Service -Status Running -StartupType Automatic -Name BrokerInfrastructure + Set-Service -Status Running -StartupType Automatic -Name BITS + Set-Service -Status Running -StartupType Automatic -Name AppHostSvc + + #Manual services + Set-Service -StartupType Manual -Name dot3svc + Set-Service -StartupType Manual -Name WaaSMedicSvc + Set-Service -StartupType Manual -Name wmiApSrv + Set-Service -StartupType Manual -Name LicenseManager + Set-Service -StartupType Manual -Name SDRSVC + Set-Service -StartupType Manual -Name TokenBroker + Set-Service -StartupType Manual -Name W3LOGSVC + Set-Service -StartupType Manual -Name VSS + Set-Service -StartupType Manual -Name UnistoreSvc_* + Set-Service -StartupType Manual -Name UserDataSvc_* + Set-Service -StartupType Manual -Name upnphost + Set-Service -StartupType Manual -Name TimeBroker + Set-Service -StartupType Manual -Name lmhosts + Set-Service -StartupType Manual -Name TieringEngineService + Set-Service -StartupType Manual -Name StorSvc + Set-Service -StartupType Manual -Name StateRepository + Set-Service -StartupType Manual -Name svsvc + Set-Service -StartupType Manual -Name seclogon + Set-Service -StartupType Manual -Name QWAVE + Set-Service -StartupType Manual -Name PrintWorkflowUserSvc_* + Set-Service -StartupType Manual -Name pla + Set-Service -StartupType Manual -Name PerfHost + Set-Service -StartupType Manual -Name defragsvc + Set-Service -StartupType Manual -Name NetSetupSvc + Set-Service -StartupType Manual -Name netprofm + Set-Service -StartupType Manual -Name Netman + Set-Service -StartupType Manual -Name InstallService + Set-Service -StartupType Manual -Name smphost + Set-Service -StartupType Manual -Name sqprv + Set-Service -StartupType Manual -Name NgcCtnrSvc + Set-Service -StartupType Manual -Name NgcSvc + Set-Service -StartupType Manual -Name MessagingService_* + Set-Service -StartupType Manual -Name wlpasvc + Set-Service -StartupType Manual -Name KtmRm + Set-Service -StartupType Manual -Name UI0Detect + Set-Service -StartupType Manual -Name PolicyAgent + Set-Service -StartupType Manual -Name IKEEXT + Set-Service -StartupType Manual -Name hidserv + Set-Service -StartupType Manual -Name hns + Set-Service -StartupType Manual -Name GraphicsPerfSvc + Set-Service -StartupType Manual -Name GraphicsPerfSvc + Set-Service -StartupType Manual -Name FDResPub + Set-Service -StartupType Manual -Name fdPHost + Set-Service -StartupType Manual -Name fhsvc + Set-Service -StartupType Manual -Name EntAppSvc + Set-Service -StartupType Manual -Name embeddedmode + Set-Service -StartupType Manual -Name DsRoleSvc + Set-Service -StartupType Manual -Name MSDTC + Set-Service -StartupType Manual -Name DevQueryBroker + Set-Service -StartupType Manual -Name DevicesFlowUserSvc_* + Set-Service -StartupType Manual -Name DevicePickerUserSvc_* + Set-Service -StartupType Manual -Name DsmSVC + Set-Service -StartupType Manual -Name DmEnrollmentSvc + Set-Service -StartupType Manual -Name DeviceInstall + Set-Service -StartupType Manual -Name DsSvc + Set-Service -StartupType Manual -Name COMSysApp + Set-Service -StartupType Manual -Name KeyIso + Set-Service -StartupType Manual -Name ClipSVC + Set-Service -StartupType Manual -Name c2wts + Set-Service -StartupType Manual -Name wbegine + Set-Service -StartupType Manual -Name aspnet_state + Set-Service -StartupType Manual -Name AssignedAccessManagerSvc + Set-Service -StartupType Manual -Name AppXSVC + Set-Service -StartupType Manual -Name AppMgmt + Set-Service -StartupType Manual -Name Appinfo + Set-Service -StartupType Manual -Name AppIDSvc + Set-Service -StartupType Manual -Name AppReadiness + Set-Service -StartupType Manual -Name AxInstSV + + #cannot be disabled but unwanted + Set-Service -Status Stopped -StartupType Manual -Name BcastDVRUserService_* + Set-Service -Status Stopped -StartupType Manual -Name DeviceAssociationService + Set-Service -Status Stopped -StartupType Manual -Name VaultSvc + Set-Service -Status Stopped -StartupType Manual -Name PimIndexMaintenanceSvc_* +} + +Export-ModuleMember -Function Disable-DefaultServices \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/Task/DisableTask.psm1 b/Scripts/Windows/MasterScriptStuff/Task/DisableTask.psm1 new file mode 100644 index 0000000..9bff41f --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/Task/DisableTask.psm1 @@ -0,0 +1,10 @@ +Function disableTasks { + Unregister-ScheduledTask -TaskPath *Bluetooth* + Unregister-ScheduledTask -TaskPath *Location* + Unregister-ScheduledTask -TaskPath *Maps* + Unregister-ScheduledTask -TaskPath *UPnP* + Unregister-ScheduledTask -TaskPath '*Plug and Play*' + Unregister-ScheduledTask -TaskPath '*Windows Error Reporting*' +} + +Export-ModuleMember -Function disableTasks diff --git a/Scripts/Windows/MasterScriptStuff/lib/Event Audit.json b/Scripts/Windows/MasterScriptStuff/lib/Event Audit.json new file mode 100644 index 0000000..c7e26ce --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/lib/Event Audit.json @@ -0,0 +1,11 @@ +{ + "AuditSystemEvents": 3, + "AuditLogonEvents": 3, + "AuditObjectAccess": 3, + "AuditPrivilegeUse": 3, + "AuditPolicyChange": 3, + "AuditAccountManage": 3, + "AuditProcessTracking": 3, + "AuditDSAccess": 3, + "AuditAccountLogon": 3 +} \ No newline at end of file diff --git a/Scripts/Windows/MasterScriptStuff/lib/System Access.json b/Scripts/Windows/MasterScriptStuff/lib/System Access.json new file mode 100644 index 0000000..e5cd209 --- /dev/null +++ b/Scripts/Windows/MasterScriptStuff/lib/System Access.json @@ -0,0 +1,14 @@ +{ + "MinimumPasswordAge": 1, + "MaximumPasswordAge": 90, + "MinimumPasswordLength": 14, + "PasswordComplexity": 1, + "PasswordHistorySize": 24, + "LockoutBadCount": 5, + "ResetLockoutCount": 15, + "LockoutDuration": 30, + "ForceLogoffWhenHourExpire": 1, + "ClearTextPassword": 0, + "EnableAdminAccount": 0, + "EnableGuestAccount": 0 +} \ No newline at end of file From 96d02990e15f7ab1e50badea1628a3afe7377f65 Mon Sep 17 00:00:00 2001 From: NotMaxwell Date: Thu, 22 Jan 2026 22:57:29 -0600 Subject: [PATCH 93/93] statrt of easy cyber patriot --- .gitignore | 40 ++++ .../CyberPatriotAutomation.csproj | 15 ++ .../Models/SystemInfo.cs | 14 ++ .../Models/TaskResult.cs | 13 ++ Scripts/CyberPatriotAutomation/Program.cs | 36 ++++ Scripts/CyberPatriotAutomation/README.md | 174 ++++++++++++++++++ .../CyberPatriotAutomation/Tasks/BaseTask.cs | 27 +++ .../Utilities/CommandExecutor.cs | 81 ++++++++ .../Utilities/ReadmeParser.cs | 55 ++++++ 9 files changed, 455 insertions(+) create mode 100644 .gitignore create mode 100644 Scripts/CyberPatriotAutomation/CyberPatriotAutomation.csproj create mode 100644 Scripts/CyberPatriotAutomation/Models/SystemInfo.cs create mode 100644 Scripts/CyberPatriotAutomation/Models/TaskResult.cs create mode 100644 Scripts/CyberPatriotAutomation/Program.cs create mode 100644 Scripts/CyberPatriotAutomation/README.md create mode 100644 Scripts/CyberPatriotAutomation/Tasks/BaseTask.cs create mode 100644 Scripts/CyberPatriotAutomation/Utilities/CommandExecutor.cs create mode 100644 Scripts/CyberPatriotAutomation/Utilities/ReadmeParser.cs diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..f255c94 --- /dev/null +++ b/.gitignore @@ -0,0 +1,40 @@ +# C# / .NET +bin/ +obj/ +*.dll +*.exe +*.pdb +*.user +*.userosscache +*.suo +*.cache +*.log + +# NuGet +*.nupkg +packages/ +*.nuget.props +*.nuget.targets + +# Visual Studio +.vs/ +*.vsidx +*.suo +*.user +*.sln.docstates + +# Rider +.idea/ + +# Build results +[Dd]ebug/ +[Rr]elease/ +x64/ +x86/ +build/ +[Bb]in/ +[Oo]bj/ + +# OS files +.DS_Store +Thumbs.db diff --git a/Scripts/CyberPatriotAutomation/CyberPatriotAutomation.csproj b/Scripts/CyberPatriotAutomation/CyberPatriotAutomation.csproj new file mode 100644 index 0000000..df600f4 --- /dev/null +++ b/Scripts/CyberPatriotAutomation/CyberPatriotAutomation.csproj @@ -0,0 +1,15 @@ + + + + Exe + net9.0 + enable + enable + + + + + + + + diff --git a/Scripts/CyberPatriotAutomation/Models/SystemInfo.cs b/Scripts/CyberPatriotAutomation/Models/SystemInfo.cs new file mode 100644 index 0000000..9f4e729 --- /dev/null +++ b/Scripts/CyberPatriotAutomation/Models/SystemInfo.cs @@ -0,0 +1,14 @@ +namespace CyberPatriotAutomation.Models; + +/// +/// Represents current system state information +/// +public class SystemInfo +{ + public string? OSVersion { get; set; } + public List RunningServices { get; set; } = new(); + public List InstalledApplications { get; set; } = new(); + public List UserAccounts { get; set; } = new(); + public List FirewallRules { get; set; } = new(); + public Dictionary RegistrySettings { get; set; } = new(); +} diff --git a/Scripts/CyberPatriotAutomation/Models/TaskResult.cs b/Scripts/CyberPatriotAutomation/Models/TaskResult.cs new file mode 100644 index 0000000..dc24bac --- /dev/null +++ b/Scripts/CyberPatriotAutomation/Models/TaskResult.cs @@ -0,0 +1,13 @@ +namespace CyberPatriotAutomation.Models; + +/// +/// Represents the result of executing a remediation task +/// +public class TaskResult +{ + public string TaskName { get; set; } = string.Empty; + public bool Success { get; set; } + public string Message { get; set; } = string.Empty; + public string? ErrorDetails { get; set; } + public DateTime ExecutedAt { get; set; } = DateTime.Now; +} diff --git a/Scripts/CyberPatriotAutomation/Program.cs b/Scripts/CyberPatriotAutomation/Program.cs new file mode 100644 index 0000000..72bc972 --- /dev/null +++ b/Scripts/CyberPatriotAutomation/Program.cs @@ -0,0 +1,36 @@ +using Spectre.Console; + +AnsiConsole.MarkupLine("[bold blue]CyberPatriot Automation Tool[/]"); +AnsiConsole.MarkupLine("[dim]Version 1.0.0[/]"); +AnsiConsole.WriteLine(); + +// Parse command line arguments +var cliArgs = Environment.GetCommandLineArgs().Skip(1).ToArray(); +var readmeFile = ExtractArgument(cliArgs, "--readme", "-r"); +var dryRun = cliArgs.Contains("--dry-run") || cliArgs.Contains("-d"); +var interactive = !cliArgs.Contains("--no-interactive"); + +if (readmeFile != null) +{ + AnsiConsole.MarkupLine($"[yellow]README: {readmeFile}[/]"); +} + +AnsiConsole.MarkupLine($"[yellow]Interactive Mode: {(interactive ? "ON" : "OFF")}[/]"); +AnsiConsole.MarkupLine($"[yellow]Dry Run: {(dryRun ? "ON" : "OFF")}[/]"); +AnsiConsole.WriteLine(); + +AnsiConsole.MarkupLine("[green]✓ Ready to scan and remediate[/]"); +AnsiConsole.MarkupLine("[dim]Implementation in progress...[/]"); + +static string? ExtractArgument(string[] args, params string[] flags) +{ + for (int i = 0; i < args.Length; i++) + { + if (flags.Contains(args[i]) && i + 1 < args.Length) + { + return args[i + 1]; + } + } + return null; +} + diff --git a/Scripts/CyberPatriotAutomation/README.md b/Scripts/CyberPatriotAutomation/README.md new file mode 100644 index 0000000..f6c8e54 --- /dev/null +++ b/Scripts/CyberPatriotAutomation/README.md @@ -0,0 +1,174 @@ +# CyberPatriot Automation Tool + +A C# console application that automates CyberPatriot competition tasks by scanning your system and executing remediation commands. + +## Features + +- **System State Reading**: Parse README files and capture current system configuration +- **Interactive Mode**: Ask for confirmation before executing each remediation +- **Dry Run Mode**: Preview changes without making them +- **Cross-Platform**: Built on .NET 9.0 for Windows, macOS, and Linux +- **Rich Terminal UI**: Beautiful formatted output with Spectre.Console + +## Project Structure + +``` +CyberPatriotAutomation/ +├── Models/ # Data classes (TaskResult, SystemInfo) +├── Tasks/ # Base task classes for remediation logic +├── Utilities/ # Helper classes (CommandExecutor, ReadmeParser) +├── Commands/ # CLI command handlers +├── Program.cs # Entry point +└── CyberPatriotAutomation.csproj +``` + +## Prerequisites + +- .NET 9.0 SDK or later +- Administrator/sudo privileges (for system remediation) + +## Installation + +1. Clone or download the project +2. Navigate to the project directory: + ```bash + cd CyberPatriotAutomation + ``` + +3. Restore dependencies: + ```bash + dotnet restore + ``` + +## Building + +```bash +dotnet build +``` + +## Running + +Basic execution: +```bash +dotnet run +``` + +With README file: +```bash +dotnet run -- --readme path/to/README.md +``` + +With options: +```bash +dotnet run -- --readme README.md --interactive --dry-run +``` + +### Command Line Arguments + +- `--readme, -r ` - Path to the CyberPatriot README file +- `--interactive, -i` - Ask for confirmation before each action (default: enabled) +- `--no-interactive` - Run without user confirmation +- `--dry-run, -d` - Show what would be done without making changes + +## Architecture + +### Models +- **TaskResult**: Represents the outcome of a task execution +- **SystemInfo**: Stores current system state (services, users, firewall rules, etc.) + +### Tasks +- **BaseTask**: Abstract base class for all remediation tasks + - `ReadSystemStateAsync()`: Gather current system information + - `ExecuteAsync()`: Perform the remediation + - `VerifyAsync()`: Confirm the fix was successful + +### Utilities +- **CommandExecutor**: Execute system commands with optional elevation + - `ExecuteAsync()`: Run a command normally + - `ExecuteElevatedAsync()`: Run with admin/sudo privileges +- **ReadmeParser**: Parse README files to extract task requirements + +## Usage Example + +```csharp +// Create a task implementation +public class DisableUnneededService : BaseTask +{ + public DisableUnneededService() + { + Name = "Disable Unnecessary Services"; + Description = "Disable services not required for the system"; + } + + public override async Task ReadSystemStateAsync() + { + var (success, output, _) = await CommandExecutor.ExecuteAsync("systemctl", "list-units --type=service"); + // Parse and return system info + return new SystemInfo(); + } + + public override async Task ExecuteAsync() + { + var (success, _, error) = await CommandExecutor.ExecuteElevatedAsync("systemctl", "disable telemetry"); + return new TaskResult + { + TaskName = Name, + Success = success, + Message = "Service disabled", + ErrorDetails = error + }; + } + + public override async Task VerifyAsync() + { + // Verify the service is actually disabled + return true; + } +} +``` + +## Development + +### Adding New Tasks + +1. Create a new class in `Tasks/` directory +2. Inherit from `BaseTask` +3. Implement the three abstract methods +4. Register in the main application logic + +### Example: File Cleaner Task + +```csharp +public class CleanTemporaryFiles : BaseTask +{ + // Implementation here +} +``` + +## Dependencies + +- **Spectre.Console** v0.54.0 - Rich terminal output +- **System.CommandLine** v2.0.2 - Command-line argument parsing + +## Notes + +- Ensure you run with elevated privileges on Windows (Run as Administrator) +- Use `--dry-run` first to preview changes +- Always backup important files before running in production +- The tool is designed for Windows systems but can be adapted for Linux/macOS + +## Future Enhancements + +- [ ] Implement specific CyberPatriot task modules +- [ ] Add progress tracking and detailed reporting +- [ ] Create task templates for common CyberPatriot categories +- [ ] Add configuration file support +- [ ] Implement logging and audit trail + +## License + +MIT License - Feel free to modify and distribute + +## Support + +For issues or suggestions, please refer to the main repository. diff --git a/Scripts/CyberPatriotAutomation/Tasks/BaseTask.cs b/Scripts/CyberPatriotAutomation/Tasks/BaseTask.cs new file mode 100644 index 0000000..ed60107 --- /dev/null +++ b/Scripts/CyberPatriotAutomation/Tasks/BaseTask.cs @@ -0,0 +1,27 @@ +using CyberPatriotAutomation.Models; + +namespace CyberPatriotAutomation.Tasks; + +/// +/// Base class for remediation tasks +/// +public abstract class BaseTask +{ + public string Name { get; protected set; } = string.Empty; + public string Description { get; protected set; } = string.Empty; + + /// + /// Read current system state for this task area + /// + public abstract Task ReadSystemStateAsync(); + + /// + /// Execute the remediation for this task + /// + public abstract Task ExecuteAsync(); + + /// + /// Verify that the remediation was successful + /// + public abstract Task VerifyAsync(); +} diff --git a/Scripts/CyberPatriotAutomation/Utilities/CommandExecutor.cs b/Scripts/CyberPatriotAutomation/Utilities/CommandExecutor.cs new file mode 100644 index 0000000..b7c2df8 --- /dev/null +++ b/Scripts/CyberPatriotAutomation/Utilities/CommandExecutor.cs @@ -0,0 +1,81 @@ +using System.Diagnostics; +using Spectre.Console; + +namespace CyberPatriotAutomation.Utilities; + +/// +/// Handles execution of system commands and processes +/// +public class CommandExecutor +{ + /// + /// Execute a command and return the output + /// + public static async Task<(bool Success, string Output, string? Error)> ExecuteAsync(string command, string? arguments = null) + { + try + { + var processInfo = new ProcessStartInfo + { + FileName = command, + Arguments = arguments ?? string.Empty, + UseShellExecute = false, + RedirectStandardOutput = true, + RedirectStandardError = true, + CreateNoWindow = true + }; + + using var process = Process.Start(processInfo); + if (process == null) + return (false, string.Empty, "Failed to start process"); + + var output = await process.StandardOutput.ReadToEndAsync(); + var error = await process.StandardError.ReadToEndAsync(); + + await Task.Run(() => process.WaitForExit()); + + return (process.ExitCode == 0, output, string.IsNullOrEmpty(error) ? null : error); + } + catch (Exception ex) + { + AnsiConsole.WriteException(ex); + return (false, string.Empty, ex.Message); + } + } + + /// + /// Execute a command with elevated privileges (requires admin/sudo) + /// + public static async Task<(bool Success, string Output, string? Error)> ExecuteElevatedAsync(string command, string? arguments = null) + { + try + { + var processInfo = new ProcessStartInfo + { + FileName = command, + Arguments = arguments ?? string.Empty, + UseShellExecute = false, + RedirectStandardOutput = true, + RedirectStandardError = true, + CreateNoWindow = true, + Verb = "runas" // Windows elevation + }; + + using var process = Process.Start(processInfo); + if (process == null) + return (false, string.Empty, "Failed to start elevated process"); + + var output = await process.StandardOutput.ReadToEndAsync(); + var error = await process.StandardError.ReadToEndAsync(); + + await Task.Run(() => process.WaitForExit()); + + return (process.ExitCode == 0, output, string.IsNullOrEmpty(error) ? null : error); + } + catch (Exception ex) + { + AnsiConsole.WriteException(ex); + return (false, string.Empty, ex.Message); + } + } +} diff --git a/Scripts/CyberPatriotAutomation/Utilities/ReadmeParser.cs b/Scripts/CyberPatriotAutomation/Utilities/ReadmeParser.cs new file mode 100644 index 0000000..6f533f4 --- /dev/null +++ b/Scripts/CyberPatriotAutomation/Utilities/ReadmeParser.cs @@ -0,0 +1,55 @@ +namespace CyberPatriotAutomation.Utilities; + +/// +/// Parses README files to extract task requirements +/// +public class ReadmeParser +{ + /// + /// Read and parse README file for task information + /// + public static async Task> ParseReadmeAsync(string filePath) + { + var tasks = new Dictionary(); + + try + { + if (!File.Exists(filePath)) + return tasks; + + var content = await File.ReadAllTextAsync(filePath); + var lines = content.Split(new[] { Environment.NewLine }, StringSplitOptions.None); + + string? currentTask = null; + var description = new List(); + + foreach (var line in lines) + { + // Check for task headers (typically marked with # or similar) + if (line.StartsWith("#") || line.StartsWith("##")) + { + if (currentTask != null && description.Count > 0) + tasks[currentTask] = string.Join(" ", description).Trim(); + + currentTask = line.TrimStart('#').Trim(); + description.Clear(); + } + else if (!string.IsNullOrWhiteSpace(line) && currentTask != null) + { + description.Add(line.Trim()); + } + } + + // Add last task + if (currentTask != null && description.Count > 0) + tasks[currentTask] = string.Join(" ", description).Trim(); + + return tasks; + } + catch (Exception ex) + { + Console.WriteLine($"Error parsing README: {ex.Message}"); + return tasks; + } + } +}